当前位置:网站首页>Wireshark data analysis and forensics a.pacapng
Wireshark data analysis and forensics a.pacapng
2022-07-03 01:27:00 【Lonely fish】
Wireshark( Pre name Ethereal) Is a network packet analysis software . The function of network packet analysis software is to retrieve network packets , At the same time, the most detailed network packet data is displayed .Wireshark Use WinPCAP As an interface , Data message exchange with network card directly .
Suppose you are a network security engineer , Need to analyze the data of a company , Analyze the operations performed by hackers to obtain computer permissions , In this chapter, we mainly analyze the key data by analyzing the case data package .
A.pacapng Data packets
1. Through analysis windows 7 Packets on the desktop A.pcapng, Find the password for the hacker to connect the Trojan horse in one sentence , Use this password as FLAG Submit ;
Screening
http
agreementctrl+F
Search for keyword@eval
2. Through analysis windows 7 Packets on the desktop A.pcapng, View call upload one sentence Trojan file ;
aaaa.php
3. By analyzing the data package A.pcapng, Find the range of network segments scanned by hackers (IP In between ”,” separate , example :192.168.1.1-192.168.1.2) Use this range as FLAG Submit ;
Screening
arp
agreement spotInfo
Sort out Here we are31
But it was swept30
Start connecting the Trojan horse To be specific, try again during the competition .
192.168.10.10-192.168.10.30
4. By analyzing the data package A.pcapng, What is the password to find the domain server , Use this password as FLAG Submit ;
163.com
5. By analyzing the data package A.pcapng, Find the file uploaded by the hacker and use the name as FLAG Submit ;
6. By analyzing the data package A.pcapng, Find out what the hacker downloaded , Treat the contents of this file as FLAG Submit ;
Put the packet into
kaili
Usebinwalk -e
To separate
Use crunch
Make a dictionary and insert it into the current directory passwd1.txt Next Use fcrackzip
Blast zip The password for encrypting the file is DBOQ6457
flag{friday}
If you don't know the place, you can confide in the blogger , Welcome to exchange !! Communication group :603813289( Just built )
Finally, if it helps you I hope you can support the blogger for the third company , Your support is my greatest motivation , Reprint please indicate the original link support original thank you !
边栏推荐
- 數學知識:臺階-Nim遊戲—博弈論
- [shutter] animation animation (shutter animation type | the core class of shutter animation)
- Give you an array numbers that may have duplicate element values. It was originally an array arranged in ascending order, and it was rotated once according to the above situation. Please return the sm
- Detailed explanation of Q-learning examples of reinforcement learning
- How wide does the dual inline for bread board need?
- LDC Build Shared Library
- Cut point of undirected graph
- 【FPGA教程案例6】基于vivado核的双口RAM设计与实现
- Concise analysis of redis source code 11 - Main IO threads and redis 6.0 multi IO threads
- Basis of information entropy
猜你喜欢
给你一个可能存在 重复 元素值的数组 numbers ,它原来是一个升序排列的数组,并按上述情形进行了一次旋转。请返回旋转数组的最小元素。【剑指Offer】
[FPGA tutorial case 6] design and implementation of dual port RAM based on vivado core
Assets, vulnerabilities, threats and events of the four elements of safe operation
【无标题】
leetcode 6103 — 从树中删除边的最小分数
[untitled]
[androd] module dependency replacement of gradle's usage skills
一位苦逼程序员的找工作经历
Meituan dynamic thread pool practice ideas, open source
JS inheritance and prototype chain
随机推荐
2022 coal mine gas drainage examination question bank and coal mine gas drainage examination questions and analysis
测试右移:线上质量监控 ELK 实战
强化学习 Q-learning 实例详解
leetcode:871. Minimum refueling times [Pat has done before + maximum stacking + greed]
Database SQL language 02 connection query
不登陆或者登录解决oracle数据库账号被锁定。
[day 29] given an integer, please find its factor number
按键精灵打怪学习-自动回城路线的判断
Mathematical Knowledge: Steps - Nim Games - Game Theory
Work experience of a hard pressed programmer
[FPGA tutorial case 5] ROM design and Implementation Based on vivado core
Is there anything in common between spot gold and spot silver
leetcode:701. Insertion in binary search tree [BST insertion]
Matlab finds the position of a row or column in the matrix
MySQL基础用法02
MySQL foundation 07-dcl
[C language] detailed explanation of pointer and array written test questions
【无标题】
Assets, vulnerabilities, threats and events of the four elements of safe operation
2022 cable crane driver examination registration and cable crane driver certificate examination