
Wireshark Workbook 1
Practice, Challenges, and Solutions
By: Laura Chappell, James Aragon (Editor)
Paperback | 11 November 2019
At a Glance
364 Pages
27.94 x 21.59 x 1.91
Paperback
$76.95
or 4 interest-free payments of $19.24 with
orShips in 5 to 7 business days
Wireshark is the world's most popular network analyzer solution. Used for network troubleshooting, forensics, optimization and more, Wireshark is considered one of the most successful open source projects of all time.
Laura Chappell has been involved in the Wireshark project since its infancy (when it was called Ethereal) and is considered the foremost authority on network protocol analysis and forensics using Wireshark.
This book consists of 16 labs and is based on the format Laura introduced to trade show audiences over ten years ago through her highly acclaimed "Packet Challenges." This book gives you a chance to test your knowledge of Wireshark and TCP/IP communications analysis by posing a series of questions related to a trace file and then providing Laura's highly detailed step-by-step instructions showing how Laura arrived at the answers to the labs.
Book trace files and blank Answer Sheets can be downloaded from this book's supplement page (see https: //www.chappell-university.com/books).
Lab 1: Wireshark Warm-Up
Objective: Get Comfortable with the Lab Process. Completion of this lab requires many of the skills you will use throughout this lab book. If you are a bit shaky on any answer, take time when reviewing the answers to this lab to ensure you have mastered the necessary skill(s).
Lab 2: Proxy Problem
Objective: Examine issues that relate to a web proxy connection problem.
Lab 3: HTTP vs. HTTPS
Objective: Analyze and compare HTTP and HTTPS communications and errors using inclusion and field existence filters.
Lab 4: TCP SYN Analysis
Objective: Filter on and analyze TCP SYN and SYN/ACK packets to determine the capabilities of TCP peers and their connections.
Lab 5: TCP SEQ/ACK Analysis
Objective: Examine and analyze TCP sequence and acknowledgment numbering and Wireshark's interpretation of non-sequential numbering patterns.
Lab 6: You're Out of Order!
Objective: Examine Wireshark's process of distinguishing between out-of-order packets and retransmissions and identify mis-identifications.
Lab 7: Sky High
Objective: Examine and analyze traffic captured as a host was redirected to a malicious site.
Lab 8: DNS Warm-Up
Objective: Examine and analyze DNS name resolution traffic that contains canonical name and multiple IP address responses.
Lab 9: Hacker Watch
Objective: Analyze TCP connections and FTP command and data channels between hosts.
Lab 10: Timing is Everything
Objective: Analyze and compare path latency, name resolution, and server response times.
Lab 11: The News
Objective: Analyze capture location, path latency, response times, and keepalive intervals between an HTTP client and server.
Lab 12: Selective ACKs
Objective: Analyze the process of establishing Selective acknowledgment (SACK) and using SACK during packet loss recovery.
Lab 13: Just DNS
Objective: Analyze, compare, and contrast various DNS queries and responses to identify errors, cache times, and CNAME (alias) information.
Lab 14: Movie Time
Objective: Use various display filter types, including regular expressions (regex), to analyze HTTP redirections, end-of-field values, object download times, errors, response times and more.
Lab 15: Crafty
Objective: Practice your display filter skills using "contains" operators, ASCII filters, and inclusion/exclusion filters, while analyzing TCP and HTTP performance parameters.
Lab 16: Pattern Recognition
Objective: Focus on TCP conversations and endpoints while analyzing TCP sequence numbers, Window Scaling, keep-alive, and Selective Acknowledgment capabilities.
Copyright Notice
About the Author
Copyright Notice
About the Author
This Book is Available as a Training Course?
Wireshark Versions Used in These Labs
How to Use This Wireshark Workbook 1
Suggested Prerequisite Knowledge to Run these Labs
Lab Preparation
Lab 1: Wireshark Warm-Up
- Objective: Get Comfortable with the Lab Process.
- Skills Covered in this Lab
Lab 2: Proxy Problem
- Objective: Examine issues that relate to a web proxy connection problem.
- Skills Covered in this Lab
Lab 3: HTTP vs. HTTPS
- Objective: Analyze and compare HTTP and HTTPS communications and errors using inclusion and field existence filters.
- Skills Covered in this Lab
Lab 4: TCP SYN Analysis
- Objective: Filter on and analyze TCP SYN and SYN/ACK packets to determine the capabilities of TCP peers and their connections.
- Skills Covered in this Lab
Lab 5: TCP SEQ/ACK Analysis
- Objective: Examine and analyze TCP sequence and acknowledgment numbering and Wireshark’s interpretation of non-sequential numbering patterns.
- Skills Covered in this Lab
Lab 6: You’re Out of Order!
- Objective: Examine Wireshark’s process of distinguishing between out-of-order packets and retransmissions and identify misidentifications.
- Skills Covered in this Lab
- Quick Test 1
- Quick Test 2
Lab 7: Sky High
- Objective: Examine and analyze traffic captured as a host was redirected to a malicious site.
- Skills Covered in this Lab
Lab 8: DNS Warm-Up
- Objective: Examine and analyze DNS name resolution traffic that contains canonical name and multiple IP address responses.
- Skills Covered in this Lab
Lab 9: Hacker Watch
- Objective: Analyze TCP connections and FTP command and data channels between hosts.
- Skills Covered in this Lab
Lab 10: Timing is Everything
- Objective: Analyze and compare path latency, name resolution, and server response times.
- Skills Covered in this Lab
Lab 11: The News
- Objective: Analyze capture location, path latency, response times, and keep-alive intervals between an HTTP client and server.
- Skills Covered in this Lab
Lab 12: Selective ACKs
- Objective: Analyze the process of establishing Selective acknowledgment (SACK) and using SACK during packet loss recovery.
- Skills Covered in this Lab
Lab 13: Just DNS
- Objective: Analyze, compare, and contrast various DNS queries and responses to identify errors, cache times, and CNAME (alias) information.
- Skills Covered in this Lab
Lab 14: Movie Time
- Objective: Use various display filter types, including regular expressions (regex), to analyze HTTP redirections, end-of-field values, object download times, errors, response times and more.
- Skills Covered in this Lab
Lab 15: Crafty
- Objective: Practice your display filter skills using “contains” operators, ASCII filters, and inclusion/exclusion filters, while analyzing TCP and HTTP performance parameters.
- Skills Covered in this Lab
Lab 16: Pattern Recognition
- Objective: Focus on TCP conversations and endpoints while analyzing TCP sequence numbers, Window Scaling, keep-alive, and Selective Acknowledgment capabilities.
- Skills Covered in this Lab
Index
ISBN: 9781893939646
ISBN-10: 1893939642
Series: Chappell University Solution Series
Published: 11th November 2019
Format: Paperback
Language: English
Number of Pages: 364
Audience: General Adult
Publisher: Protocol Analysis Institute, Inc.
Dimensions (cm): 27.94 x 21.59 x 1.91
Weight (kg): 0.84
Shipping
| Standard Shipping | Express Shipping | |
|---|---|---|
| Metro postcodes: | $9.99 | $14.95 |
| Regional postcodes: | $9.99 | $14.95 |
| Rural postcodes: | $9.99 | $14.95 |
Orders over $79.00 qualify for free shipping.
How to return your order
At Booktopia, we offer hassle-free returns in accordance with our returns policy. If you wish to return an item, please get in touch with Booktopia Customer Care.
Additional postage charges may be applicable.
Defective items
If there is a problem with any of the items received for your order then the Booktopia Customer Care team is ready to assist you.
For more info please visit our Help Centre.
You Can Find This Book In

IPv6 Fundamentals
Packet and Data Structures, Addressing Architecture, Device Discovery, and Configuration Protocols
Hardcover
RRP $105.00
$92.75
OFF

IPv6 Fundamentals
Packet and Data Structures, Addressing Architecture, Device Discovery, and Configuration Protocols
Paperback
RRP $158.00
$141.75
OFF






















