All language subtitles for 13. Wireshark - Sniffing & Analysing Data

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic Download
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranî)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

In the previous video 2

2

we seen how we can launch Wireshark 3

3

and we said that we can actually just open 4

4

a file that contains packets that we already captured 5

5

and we can start analyzing them using Wireshark. 6

6

In this video I want to start sniffing packets 7

7

and then generate some traffic 8

8

in my Windows machine 9

9

and then we'll see how 10

10

we can analyze these packets using Wireshark. 11

11

So I'm already the man in the middle 12

12

as I've said you first have to be the 13

13

man in the middle to use Wireshark 14

14

and then the traffic that's generated 15

15

in the Windows machine is actually 16

16

filmed through eth0 as we seen in the previous video. 17

17

So before I start capturing the packets, 18

18

I wanna go to the options 19

19

and I just wanna show you what options we can set. 20

20

So first you can see all the interfaces 21

21

that you have and you can see the traffic generated on them. 22

22

And you can see eth0 is actually generating 23

23

some traffic every now and then 24

24

because it's actually coming from the Windows machine. 25

25

So in here you can select the interfaces 26

26

that you want to start capturing on 27

27

and you can actually select more than one interface 28

28

and all we have to do is just hold the control 29

29

and then click other interfaces 30

30

that you want to listen on. 31

31

For example, we can just click them like this. 32

32

But for now I actually only wanna sniff on eth0. 33

33

Now if we go on the output 34

34

you'll see that you have an option to store 35

35

these packets somewhere 36

36

so again if you only want to sniff 37

37

and you don't want to analyze things 38

38

then you can just go onto browse 39

39

and you can store the packets 40

40

that you're gonna sniff somewhere 41

41

and then you can analyze them whenever you have the time. 42

42

At a different time you can just open 43

43

them with Wireshark like I showed you 44

44

in the previous video, 45

45

you can just go on file, open 46

46

and then open the packets and start analyzing them. 47

47

Now I have eth0 selected 48

48

and I'm just gonna click on start. 49

49

And that will start capturing packets. 50

50

Anything that's gonna flow through eth0 51

51

will be captured and it will be displayed in here, anything. 52

52

I mean images, pictures, messages, cookies, 53

53

anything that that computer does on the internet 54

54

will flow through eth0 and therefore 55

55

will be captured by Wireshark. 56

56

So it's not like man in the middle life 57

57

where it was only showing us the important 58

58

information right here you'll see anything, 59

59

all the traffic that's generated. 60

60

Now, I wanna go and generate some traffic 61

61

on the target computer so we can analyze it here 62

62

but before I do that 63

63

I'm gonna go back to buttercup 64

64

and I wanna see my hsts caplet 65

65

so I can downgrade https to http 66

66

'cause if everything goes over http 67

67

we won't be able to see or read anything 68

68

because like I said, 69

69

everything will be encrypted. 70

70

So I'm gonna hit enter 71

71

this will work as expected, 72

72

we'll go back to Wireshark 73

73

and let's go to the target computer. 74

74

I'm gonna go to google.ie 75

75

and let's search for something 76

76

so for example let's search for zSecurity 77

77

and keep in mind everything is loading 78

78

over http in here so that's why we'll be able to read 79

79

and analyze everything that we're loading right here. 80

80

Now, let's go back to Wireshark 81

81

and see how we can filter this information 82

82

and discover the websites visit 83

83

by the target, see the requests, and all that. 84

84

So I'm gonna click on the stop button to stop this. 85

85

Now this is the main interface of Wireshark 86

86

and you can see that the first thing we have 87

87

is each one record of this is a packet. 88

88

Now you'll see here the columns, 89

89

first of all here is the number of the packets 90

90

so you have this one is number one, 91

91

number two, number three and number four. 92

92

And the time, 93

93

you'll see the time when this packet was captured 94

94

so zero is when we first started sniffing 95

95

and then the time increases as we go down 96

96

and it shows when these packets were captured, 97

97

when they were sent basically. 98

98

You can also see the source, 99

99

so this is the device that the packet was sent from 100

100

and you can see that this one is not sent 101

101

from our target it's actually coming from the internet 102

102

from a server that has this IP 103

103

and it's going to our target computer 104

104

which is 10.20.14.206. 105

105

You can see the protocol so it's TCP for this one. 106

106

You can see that it's ICMP in this one 107

107

and you can see that it's ARP for this. 108

108

You can see the length which is the size 109

109

and you can also see info about this packet. 110

110

Now we can also notice that 111

111

these packets have different colors. 112

112

Usually green is TCP packets, 113

113

dark blue is DNS packets, 114

114

and if we go down we should actually be able to find 115

115

some of them and you can see all of these are DNF packets. 116

116

Light blue usually is UDP 117

117

but we don't have any UDP packets at the moment. 118

118

And you can also see we have some black packets 119

119

and these are TCP packets that 120

120

had a problem, that had issues. 121

121

Now I know what you're thinking, 122

122

there are so many packets in here 123

123

and a lot of them might not be useful to you 124

124

depending on what you're trying to get. 125

125

But don't worry about this, 126

126

in the next lecture I'm gonna show you 127

127

how to filter these packets to only display 128

128

the relevant ones and then analyze them 129

129

to extract the useful information.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.