Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
In the previous video 2
2
we seen how we can launch Wireshark 3
3
and we said that we can actually just open 4
4
a file that contains packets that we already captured 5
5
and we can start analyzing them using Wireshark. 6
6
In this video I want to start sniffing packets 7
7
and then generate some traffic 8
8
in my Windows machine 9
9
and then we'll see how 10
10
we can analyze these packets using Wireshark. 11
11
So I'm already the man in the middle 12
12
as I've said you first have to be the 13
13
man in the middle to use Wireshark 14
14
and then the traffic that's generated 15
15
in the Windows machine is actually 16
16
filmed through eth0 as we seen in the previous video. 17
17
So before I start capturing the packets, 18
18
I wanna go to the options 19
19
and I just wanna show you what options we can set. 20
20
So first you can see all the interfaces 21
21
that you have and you can see the traffic generated on them. 22
22
And you can see eth0 is actually generating 23
23
some traffic every now and then 24
24
because it's actually coming from the Windows machine. 25
25
So in here you can select the interfaces 26
26
that you want to start capturing on 27
27
and you can actually select more than one interface 28
28
and all we have to do is just hold the control 29
29
and then click other interfaces 30
30
that you want to listen on. 31
31
For example, we can just click them like this. 32
32
But for now I actually only wanna sniff on eth0. 33
33
Now if we go on the output 34
34
you'll see that you have an option to store 35
35
these packets somewhere 36
36
so again if you only want to sniff 37
37
and you don't want to analyze things 38
38
then you can just go onto browse 39
39
and you can store the packets 40
40
that you're gonna sniff somewhere 41
41
and then you can analyze them whenever you have the time. 42
42
At a different time you can just open 43
43
them with Wireshark like I showed you 44
44
in the previous video, 45
45
you can just go on file, open 46
46
and then open the packets and start analyzing them. 47
47
Now I have eth0 selected 48
48
and I'm just gonna click on start. 49
49
And that will start capturing packets. 50
50
Anything that's gonna flow through eth0 51
51
will be captured and it will be displayed in here, anything. 52
52
I mean images, pictures, messages, cookies, 53
53
anything that that computer does on the internet 54
54
will flow through eth0 and therefore 55
55
will be captured by Wireshark. 56
56
So it's not like man in the middle life 57
57
where it was only showing us the important 58
58
information right here you'll see anything, 59
59
all the traffic that's generated. 60
60
Now, I wanna go and generate some traffic 61
61
on the target computer so we can analyze it here 62
62
but before I do that 63
63
I'm gonna go back to buttercup 64
64
and I wanna see my hsts caplet 65
65
so I can downgrade https to http 66
66
'cause if everything goes over http 67
67
we won't be able to see or read anything 68
68
because like I said, 69
69
everything will be encrypted. 70
70
So I'm gonna hit enter 71
71
this will work as expected, 72
72
we'll go back to Wireshark 73
73
and let's go to the target computer. 74
74
I'm gonna go to google.ie 75
75
and let's search for something 76
76
so for example let's search for zSecurity 77
77
and keep in mind everything is loading 78
78
over http in here so that's why we'll be able to read 79
79
and analyze everything that we're loading right here. 80
80
Now, let's go back to Wireshark 81
81
and see how we can filter this information 82
82
and discover the websites visit 83
83
by the target, see the requests, and all that. 84
84
So I'm gonna click on the stop button to stop this. 85
85
Now this is the main interface of Wireshark 86
86
and you can see that the first thing we have 87
87
is each one record of this is a packet. 88
88
Now you'll see here the columns, 89
89
first of all here is the number of the packets 90
90
so you have this one is number one, 91
91
number two, number three and number four. 92
92
And the time, 93
93
you'll see the time when this packet was captured 94
94
so zero is when we first started sniffing 95
95
and then the time increases as we go down 96
96
and it shows when these packets were captured, 97
97
when they were sent basically. 98
98
You can also see the source, 99
99
so this is the device that the packet was sent from 100
100
and you can see that this one is not sent 101
101
from our target it's actually coming from the internet 102
102
from a server that has this IP 103
103
and it's going to our target computer 104
104
which is 10.20.14.206. 105
105
You can see the protocol so it's TCP for this one. 106
106
You can see that it's ICMP in this one 107
107
and you can see that it's ARP for this. 108
108
You can see the length which is the size 109
109
and you can also see info about this packet. 110
110
Now we can also notice that 111
111
these packets have different colors. 112
112
Usually green is TCP packets, 113
113
dark blue is DNS packets, 114
114
and if we go down we should actually be able to find 115
115
some of them and you can see all of these are DNF packets. 116
116
Light blue usually is UDP 117
117
but we don't have any UDP packets at the moment. 118
118
And you can also see we have some black packets 119
119
and these are TCP packets that 120
120
had a problem, that had issues. 121
121
Now I know what you're thinking, 122
122
there are so many packets in here 123
123
and a lot of them might not be useful to you 124
124
depending on what you're trying to get. 125
125
But don't worry about this, 126
126
in the next lecture I'm gonna show you 127
127
how to filter these packets to only display 128
128
the relevant ones and then analyze them 129
129
to extract the useful information.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.