tcpdump-wireshark

30

Upload: harsh-singh

Post on 30-Jan-2015

3.579 views

Category:

Technology


1 download

DESCRIPTION

 

TRANSCRIPT

Page 1: TCPdump-Wireshark
Page 2: TCPdump-Wireshark

Line ups:

Amar The Rock Anil The Assassin

Harsh The Conductor Atomic Ant Ganeshan

Terrible Tabrez Himanshu The Wonder Kid

Pavan The Powerhouse Manjunath The Spark

Page 3: TCPdump-Wireshark
Page 4: TCPdump-Wireshark

1. Introduction. 1. Introduction.2. Prerequisite – TCP/IP model. 2. Installation.3. Installation. 3. Analysis.4. Commands -------------------------------------------------Demo----------------------------------------------------------------------------------------------------Packet Analysis----------------------------------------------------------------------------------COMPARISON B/W TCPdump and NPA------------------------------------------------------------------------------- Acknowledgement--------------------------------------------------

Page 5: TCPdump-Wireshark

What is TCPdump????

Characteristics of TCPdump

How and where is it used????

Page 6: TCPdump-Wireshark

Transmission Media

Page 7: TCPdump-Wireshark

TCP dump can be installed in many ways in Linux(Ubuntu):

1.Synaptic Packet Manager

i.Searching through in Synaptic Packet Manager for tcpdump.ii.Downloading and installing from the provided options.

1.Through Terminal

i.Terminal is to be opened.ii.sudo su -> prompts for a password and please do enter it.iii.#apt –get install tcpdump

Page 8: TCPdump-Wireshark

#t

#tcpdump#

Page 9: TCPdump-Wireshark

10/26/09

#tcpdump -v

Page 10: TCPdump-Wireshark

10/26/09

#tcpdump -n

Page 11: TCPdump-Wireshark

10/26/09

#tcpdump -D

Page 12: TCPdump-Wireshark

10/26/09

#tcpdump -q

Page 13: TCPdump-Wireshark

10/26/09

#tcpdump udp

Page 14: TCPdump-Wireshark

10/26/09

Page 15: TCPdump-Wireshark
Page 16: TCPdump-Wireshark

NETWORK PROTOCAL ANALIYSIS DEFINITION ?

INTRODUCTION TO WIRESHARK

FEATURES OF WIRESHARK

WHY IS WIRESHARK PREFERED OVER TCPDUMP ?

Page 17: TCPdump-Wireshark

Computer s/w or h/w, intercepts & logs traffic passing over the networkCaptures packets, decodes & analyzes contentsA network Analyzer is used for

Troubleshooting problems on the networkAnalyzing the performance of a network to discover

bottlenecksNetwork intrusion detectionAnalyzing the operations of applications

Page 18: TCPdump-Wireshark

It is a packet sniffer Computer application

Functionality is very similar to tcpdump

Has a GUI front-end and many more information sorting and filtering options

Page 19: TCPdump-Wireshark

Download and install

Page 20: TCPdump-Wireshark

# apt-get install wireshark

Page 21: TCPdump-Wireshark

10/26/09

Page 22: TCPdump-Wireshark

10/26/09

Page 23: TCPdump-Wireshark

This checkbox allows you to specify that Wireshark should put the interface in promiscuous mode when capturing. If you do not specify this, Wireshark will only capture the packets going to or from your computer (not all packets on your LAN segment).

Page 24: TCPdump-Wireshark

Exposing VOIP problems

Supports Malware Detection

Helps recognize DOS attack

Downloading FLV files

Page 25: TCPdump-Wireshark

10/26/09

Page 26: TCPdump-Wireshark

10/26/09

Here is a quick reference for TCP flags:

Page 27: TCPdump-Wireshark

10/26/09

4510 0068 7e87 4000 4006 3862 c0a8 011ec0a8 0128 0016 0479 b6c8 a8de 621e 87db5018 4470 1813 0000 e492 152f 23c3 8a2b4ee7 dbf8 0d48 88e8 0110 2b01 4295 39f452c9 a05b 31d7 e3ae 1c62 2dbd d955 d604b5d2 63d1 8fbc 4ab7 1615 b382 571c 70e0a368 a03f 425b 6211

Page 28: TCPdump-Wireshark

10/26/09

TCPdump Network Protocol Analyzer

No Proper Interface Decent Graphical User Interface

Uncontrolled Output Decently Sorted Output

It is an old tool More modern tool

No Graph Graph can be viewed

Have to remember all the commands

All commands are available in the GUI

Not user friendly, but hardcore programmer friendly

User Friendly

Page 29: TCPdump-Wireshark

10/26/09

Page 30: TCPdump-Wireshark

10/26/0910/26/09

We thank our referee(s) for the game, we invite your suggestions and comments.

For audience/fans, a post match press conference will be held which is for questions on the match….

Thank you