Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
In this lecture, I wanna spend more time 2
2
with Wireshark showing you how to filter all 3
3
of these packets to only display the useful packets, 4
4
how to trace them, what do they mean, 5
5
and how to display more information about 6
6
each one of these packets. 7
7
Now what we did on the target computer so far, 8
8
we most of the traffic that we generated 9
9
was HTTP traffic, 10
10
so to get rid of all this information that's hard 11
11
for us to read, 12
12
we're just gonna type in here in the filters. 13
13
We're just gonna type in http. 14
14
Hit enter, 15
15
and as you can see now that filtered all the packets 16
16
to HTTP traffic only. 17
17
So this is the traffic that was basically sent 18
18
by the browser and is usually sent by web browsers. 19
19
They always send traffic over HTTP or HTTPS. 20
20
And since we're downgraded HTTPS to HTTP, 21
21
you wanna use the HTTP filter to see everything 22
22
that a target person is doing on the browser, 23
23
regardless of what they're doing. 24
24
Whether they're browsing websites, 25
25
whether they're watching a video, 26
26
whether they're looking at images, 27
27
whatever they're looking, it will be loaded over HTTP. 28
28
So looking at the first record right here, 29
29
we can see that this request is sent from 30
30
this IP, which is the IP of my target 31
31
to an IP on the internet. 32
32
So we can see that this is not a private IP, 33
33
this is an IP on the internet. 34
34
So it's sent to a server. 35
35
And if we double click this record, 36
36
we'll get much more information about the packet itself. 37
37
So we have the information about the frame, 38
38
which includes the size of the packet. 39
39
It includes the interface that it was sent on, 40
40
the time, and all that. 41
41
In the internet, we have information about the source MAC 42
42
address and the destination MAC address. 43
43
So where did this packet go from and where did it go to? 44
44
Remember when I first spoke about packets and how 45
45
they always travel from a source MAC to a destination MAC? 46
46
So this information is all stored in here. 47
47
In the internet protocol, we have information about 48
48
the IPs, so in the internet we had information about 49
49
the MAC addresses. 50
50
In the internet protocol, we have information about 51
51
the source IP and the destination IP 52
52
for this particular packet. 53
53
And the transmission protocol we have information 54
54
about the port, so we can see that this went from this 55
55
source port to port 80. 56
56
This is usually the default port used on web servers, 57
57
so in most cases whenever data is sent to a website, 58
58
it'll always be sent to port 80. 59
59
But the most important part in here is the hypertext 60
60
transfer protocol, which is basically the data sent 61
61
over HTTP. 62
62
Clicking on this will give us information on whatever 63
63
data has been sent over HTTP. 64
64
And like I said, this would contain everything 65
65
that was sent to and from a browser. 66
66
So right here we can see that this particular packet 67
67
sent a get request to a website called google.ie. 68
68
Now this is literally when we typed google.ie, 69
69
we didn't search for anything. 70
70
We didn't really do anything. 71
71
You can also expand this to see more information 72
72
about the actual request. 73
73
And you can even see the HTTP header sent if you wanna 74
74
get more information about this particular request. 75
75
Now this whole method of getting information follows 76
76
with all types of packets, 77
77
so you can double click any packet you have 78
78
and you'll be able to read the data sent 79
79
within this packet. 80
80
Now you can also in here see an arrow, 81
81
which basically means that this was a request 82
82
and the arrow back here marks that this was 83
83
a response to this request right here. 84
84
Now moving down you can see also see requests 85
85
for images. 86
86
What you can also do is click on any of these packets, 87
87
for example, again back to this get request, 88
88
right click it, and go to Follow HTTP Stream. 89
89
And this will basically follow the stream 90
90
that this request has caused, all the way down 91
91
to the response. 92
92
So if I click it, you'll see the response for this 93
93
particular request was this right here. 94
94
You can see that this was a PNG, 95
95
and literally the binary content of this PNG image 96
96
is right here. 97
97
So as you can see we're literally getting the raw data 98
98
in here. 99
99
Now I'm gonna close this and go back to what we had, 100
100
which was HTTP. 101
101
Now if we keep going down. 102
102
You literally see everything that has been sent 103
103
and received by the target. 104
104
So, for example, again in here we can see this was 105
105
a JavaScript file that was loaded by Google. 106
106
Then in here we can see another get request. 107
107
And this get request was where we searched for 108
108
that security, so you can even see the search term in here. 109
109
So let me double click this to show you in more details. 110
110
Again, this automatically went 111
111
to the hypertext protocol part. 112
112
Like I said, this is the HTTP part. 113
113
Whatever that gets sent to the browser, 114
114
and you can see that this was sent to google.com 115
115
first of all and the URI, so whatever went after 116
116
google.com was search and what we were searching 117
117
for that zsecurity which is exactly what we typed in here. 118
118
Again, in here you can see the full URL 119
119
with the search term. 120
120
This is literally what the user gets and their URL 121
121
bar in here. 122
122
So as you can see Wireshark literally shows everything 123
123
that flows through the interface. 124
124
In this lecture I wanted to show you a quick overview 125
125
on how we can filter data. 126
126
And don't worry too much about this. 127
127
We'll actually be using it more in the next lectures 128
128
and we will see how we can easily use it 129
129
to filter data and discover useful information.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.