DCCN Assingnment JP
DCCN Assingnment JP
Faculty - J.K.Naik
ti
ti
Enrollment No:-230170132036
Conclusion
ti
fi
ti
ti
fi
ti
ti
fi
fl
ti
Enrollment No:-230170132036
h p://example.com
o Since most modern websites use HTTPS (port 443),
you may need to use an older or internal site that
s ll supports HTTP.
o Alterna vely, set up a local HTTP server using
Python:
python -m h p.server 80
o Then access h p://localhost in your browser.
6. Stop the Capture
• Once you have generated enough tra c, click Stop in
Wireshark.
Conclusion
Wireshark is a powerful tool for capturing and analyzing
HTTP tra c. By ltering and inspec ng requests and
responses, you can troubleshoot web communica on
issues, analyze website behavior, and even extract data.
ffi
fi
fi
ti
ti
fi
ti
ti
Enrollment No:-230170132036
▪ If the MAC address of the des na on is not cached, an ARP request is sent.
6. Stop the Capture
• A er genera ng some ARP tra c, click the Stop bu on in Wireshark.
o Sender MAC Address: The device asking for the MAC address.
o Sender IP Address: The IP address associated with the sender.
o Target MAC Address: 00:00:00:00:00:00 (unknown, reques ng resolu on).
o Target IP Address: The IP address being queried.
o Opera on (Opcode): 1 (Request).
4. Inspect ARP Reply Packets
• Click on an ARP Reply packet and check:
o Sender MAC Address: The device responding with its MAC address.
o Sender IP Address: The IP address being resolved.
o Target MAC Address: The original requester's MAC address.
o Target IP Address: The original requester's IP.
o Opera on (Opcode): 2 (Reply).
5. Detect ARP Spoo ng or A acks
• If you no ce mul ple ARP responses with di erent MAC addresses for the same IP, it might
indicate ARP spoo ng (man-in-the-middle a ack).
• Use this lter to check for duplicate IPs with di erent MACs:
arp.duplicate-address-detected
Conclusion
Wireshark makes it easy to analyze ARP requests and replies, troubleshoot network issues,
and detect security threats like ARP spoo ng. ARP is essen al for device communica on
within a local network, and monitoring it can help iden fy connec vity problems.
ti
ti
fi
ti
ti
fi
fi
tt
fi
tt
ff
ff
ti
ti
ti
ti
ti
ti
Enrollment No:-230170132036
Enrollment No:-230170132036
Conclusion
Wireshark allows deep inspec on of TCP tra c, helping diagnose connec on issues,
retransmissions, and performance bo lenecks. Understanding TCP behavior is crucial for
troubleshoo ng networks and analyzing web tra c.
ti
ti
tt
ffi
ffi
ti
Enrollment No:-230170132036
The Internet Protocol (IP) is the founda on of network communica on, responsible for
addressing and rou ng packets between devices. In Wireshark, you can capture and analyze
IP tra c to diagnose network issues, monitor data ow, and detect poten al threats.
ffi
ti
ffi
ti
fl
ti
ti
Enrollment No:-230170132036
Conclusion
Wireshark makes it easy to capture and analyze IP tra c, helping diagnose rou ng issues,
fragmenta on, and unusual network behavior.
fl
ti
ti
fi
ti
fi
ti
fi
ti
ti
ti
ti
ti
ffi
fi
ti
fi
ff
ti
ff
ti
ti
ti
ffi
ti
ti
ti
ffi
ti
fi
ti
ti
ffi
fi
ti
tt
ti
Enrollment No:-230170132036