你有问题,我有答案。
前言
题目信息
数据包信息
λ capinfos whatsup.pcapng
File name: whatsup.pcapng
File type: Wireshark/... - pcapng
File encapsulation: Ethernet
File timestamp precision: microseconds (6)
Packet size limit: file hdr: (not set)
Number of packets: 52
File size: 34 kB
Data size: 32 kB
Capture duration: 65.134372 seconds
First packet time: 2014-08-21 11:14:34.045564
Last packet time: 2014-08-21 11:15:39.179936
Data byte rate: 498 bytes/s
Data bit rate: 3989 bits/s
Average packet size: 624.65 bytes
Average packet rate: 0 packets/s
SHA256: f977684e55b4bd48479781547c4e510cb89367785917a4d94c743e93193fff2e
RIPEMD160: fa09efc58691773c2636bbd4d0f844a4f8eb8834
SHA1: d91aa2ab506b07ddb4653728c28983e2e996635c
Strict time order: True
Capture oper-sys: 64-bit Windows 8, build 9200
Capture application: Dumpcap 1.10.9 (v1.10.9-0-g6b041ab from master-1.10)
Number of interfaces in file: 1
Interface #0 info:
Name = DeviceNPF_{BD0C1124-CBA7-41BB-95BA-DB895B9631F2}
Encapsulation = Ethernet (1 - ether)
Capture length = 262144
Time precision = microseconds (6)
Time ticks per second = 1000000
Time resolution = 0x06
Operating system = 64-bit Windows 8, build 9200
Number of stat entries = 1
Number of packets = 52
Number of resolved IPv4 addresses in file: 1
λ
数据包分析
Packet List
最右侧会有明显的黑红色告警信息的提示。1. Why did a device send an ICMP Type 3/Code 4 packet in this trace file?
分析步骤
TYPE | CODE | Description | Error |
3 |
4 | Fragmentation needed but no frag. bit set—需要进行分片但设置不分片比特 | x |
分析答案
2. What was the MTU size before the drop in size?
分析步骤
分析答案
3. What is the IP address of the router that can’t forward larger sized frames?
分析步骤
稍微有点问题的地方是,该 IP 和原始数据包的目的 IP 均是同一个,疑似匿名化数据包该 IP 时弄错了。。。
分析答案
4. What is the IP address of the host that adjusted its MTU?
分析步骤
分析答案
5. How many more frames would be required to send a 6,000‐byte file using the smaller MTU size than using the larger MTU size?
分析步骤
分析答案
往期推荐
原文始发于微信公众号(Echo Reply):Wireshark TS | Packet Challenge 之 MTU 案例分析
免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论