All language subtitles for 14. Wireshark - Using Filters, Tracing & Dissecting Packets

af Afrikaans
ak Akan
sq Albanian
am Amharic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

In this lecture, I wanna spend more time 2

2

with Wireshark showing you how to filter all 3

3

of these packets to only display the useful packets, 4

4

how to trace them, what do they mean, 5

5

and how to display more information about 6

6

each one of these packets. 7

7

Now what we did on the target computer so far, 8

8

we most of the traffic that we generated 9

9

was HTTP traffic, 10

10

so to get rid of all this information that's hard 11

11

for us to read, 12

12

we're just gonna type in here in the filters. 13

13

We're just gonna type in http. 14

14

Hit enter, 15

15

and as you can see now that filtered all the packets 16

16

to HTTP traffic only. 17

17

So this is the traffic that was basically sent 18

18

by the browser and is usually sent by web browsers. 19

19

They always send traffic over HTTP or HTTPS. 20

20

And since we're downgraded HTTPS to HTTP, 21

21

you wanna use the HTTP filter to see everything 22

22

that a target person is doing on the browser, 23

23

regardless of what they're doing. 24

24

Whether they're browsing websites, 25

25

whether they're watching a video, 26

26

whether they're looking at images, 27

27

whatever they're looking, it will be loaded over HTTP. 28

28

So looking at the first record right here, 29

29

we can see that this request is sent from 30

30

this IP, which is the IP of my target 31

31

to an IP on the internet. 32

32

So we can see that this is not a private IP, 33

33

this is an IP on the internet. 34

34

So it's sent to a server. 35

35

And if we double click this record, 36

36

we'll get much more information about the packet itself. 37

37

So we have the information about the frame, 38

38

which includes the size of the packet. 39

39

It includes the interface that it was sent on, 40

40

the time, and all that. 41

41

In the internet, we have information about the source MAC 42

42

address and the destination MAC address. 43

43

So where did this packet go from and where did it go to? 44

44

Remember when I first spoke about packets and how 45

45

they always travel from a source MAC to a destination MAC? 46

46

So this information is all stored in here. 47

47

In the internet protocol, we have information about 48

48

the IPs, so in the internet we had information about 49

49

the MAC addresses. 50

50

In the internet protocol, we have information about 51

51

the source IP and the destination IP 52

52

for this particular packet. 53

53

And the transmission protocol we have information 54

54

about the port, so we can see that this went from this 55

55

source port to port 80. 56

56

This is usually the default port used on web servers, 57

57

so in most cases whenever data is sent to a website, 58

58

it'll always be sent to port 80. 59

59

But the most important part in here is the hypertext 60

60

transfer protocol, which is basically the data sent 61

61

over HTTP. 62

62

Clicking on this will give us information on whatever 63

63

data has been sent over HTTP. 64

64

And like I said, this would contain everything 65

65

that was sent to and from a browser. 66

66

So right here we can see that this particular packet 67

67

sent a get request to a website called google.ie. 68

68

Now this is literally when we typed google.ie, 69

69

we didn't search for anything. 70

70

We didn't really do anything. 71

71

You can also expand this to see more information 72

72

about the actual request. 73

73

And you can even see the HTTP header sent if you wanna 74

74

get more information about this particular request. 75

75

Now this whole method of getting information follows 76

76

with all types of packets, 77

77

so you can double click any packet you have 78

78

and you'll be able to read the data sent 79

79

within this packet. 80

80

Now you can also in here see an arrow, 81

81

which basically means that this was a request 82

82

and the arrow back here marks that this was 83

83

a response to this request right here. 84

84

Now moving down you can see also see requests 85

85

for images. 86

86

What you can also do is click on any of these packets, 87

87

for example, again back to this get request, 88

88

right click it, and go to Follow HTTP Stream. 89

89

And this will basically follow the stream 90

90

that this request has caused, all the way down 91

91

to the response. 92

92

So if I click it, you'll see the response for this 93

93

particular request was this right here. 94

94

You can see that this was a PNG, 95

95

and literally the binary content of this PNG image 96

96

is right here. 97

97

So as you can see we're literally getting the raw data 98

98

in here. 99

99

Now I'm gonna close this and go back to what we had, 100

100

which was HTTP. 101

101

Now if we keep going down. 102

102

You literally see everything that has been sent 103

103

and received by the target. 104

104

So, for example, again in here we can see this was 105

105

a JavaScript file that was loaded by Google. 106

106

Then in here we can see another get request. 107

107

And this get request was where we searched for 108

108

that security, so you can even see the search term in here. 109

109

So let me double click this to show you in more details. 110

110

Again, this automatically went 111

111

to the hypertext protocol part. 112

112

Like I said, this is the HTTP part. 113

113

Whatever that gets sent to the browser, 114

114

and you can see that this was sent to google.com 115

115

first of all and the URI, so whatever went after 116

116

google.com was search and what we were searching 117

117

for that zsecurity which is exactly what we typed in here. 118

118

Again, in here you can see the full URL 119

119

with the search term. 120

120

This is literally what the user gets and their URL 121

121

bar in here. 122

122

So as you can see Wireshark literally shows everything 123

123

that flows through the interface. 124

124

In this lecture I wanted to show you a quick overview 125

125

on how we can filter data. 126

126

And don't worry too much about this. 127

127

We'll actually be using it more in the next lectures 128

128

and we will see how we can easily use it 129

129

to filter data and discover useful information.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.