CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 1182
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 1182: 1514 bytes on wire (12112 bits), 1514 bytes captured (12112 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 04:54:04.453081000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508561644.453081000 seconds
[Time delta from previous captured frame: 0.000010000 seconds]
[Time delta from previous displayed frame: 0.000010000 seconds]
[Time since reference or first frame: 131.139578000 seconds]
Frame Number: 1182
Frame Length: 1514 bytes (12112 bits)
Capture Length: 1514 bytes (12112 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:data]
Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 35.198.166.240, Dst: 10.0.1.95
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 1500
Identification: 0x0d02 (3330)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0x5205 [validation disabled]
[Header checksum status: Unverified]
Source Address: 35.198.166.240
Destination Address: 10.0.1.95
[Source GeoIP: Frankfurt am Main, DE, ASN 396982, GOOGLE-CLOUD-PLATFORM]
[Source GeoIP City: Frankfurt am Main]
[Source or Destination GeoIP City: Frankfurt am Main]
[Source GeoIP Country: Germany]
[Source or Destination GeoIP Country: Germany]
[Source GeoIP ISO Two Letter Country Code: DE]
[Source or Destination GeoIP ISO Two Letter Country Code: DE]
[Source GeoIP AS Number: 396982]
[Source or Destination GeoIP AS Number: 396982]
[Source GeoIP AS Organization: GOOGLE-CLOUD-PLATFORM]
[Source or Destination GeoIP AS Organization: GOOGLE-CLOUD-PLATFORM]
[Source GeoIP Latitude: 50.1169]
[Source or Destination GeoIP Latitude: 50.1169]
[Source GeoIP Longitude: 8.6837]
[Source or Destination GeoIP Longitude: 8.6837]
Transmission Control Protocol, Src Port: 80, Dst Port: 57622, Seq: 120577, Ack: 1647, Len: 1460
Source Port: 80
Destination Port: 57622
[Stream index: 39]
[Conversation completeness: Complete, WITH_DATA (47)]
[TCP Segment Len: 1460]
Sequence Number: 120577 (relative sequence number)
Sequence Number (raw): 293771305
[Next Sequence Number: 122037 (relative sequence number)]
Acknowledgment Number: 1647 (relative ack number)
Acknowledgment number (raw): 308123420
0101 .... = Header Length: 20 bytes (5)
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······A····]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x1c24 [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 1.125875000 seconds]
[Time since previous frame in this TCP stream: 0.000010000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.161371000 seconds]
[Bytes in flight: 5376]
[Bytes sent since last PSH flag: 2920]
TCP payload (1460 bytes)
Hypertext Transfer Protocol
1��j�jOSO�ʇ�Ä/!�5�\f�`\032H�+���"\030e��5\020�\006L��.74J��\035�b������6:�� �VR\000c�n�*s�d\000]����\030\aC �\024CP�?��@7kp�uK<�"��\r
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
[truncated]c�7\001���\024���\025�E�T����Iv$�\030��/�!�Q]��ہGv��9Yrk��rs7\031&�yW���&;�+P�}e�H�w��\023����W'�l_�߷\f>\032쁮��^Ã5d"����\024�F+
[Expert Info (Warning/Undecoded): Trailing stray characters]
[Trailing stray characters]
[Severity level: Warning]
[Group: Undecoded]
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
[truncated]c������tC�X�����s\021\004�f�\022\001:���:l\026Cȋvp ��D�![�.H��\017i\vW�\016�)]��\031��8��iw��߹Fd�s&��{��\035L4�")_.E\i\027��2bi�v\177��+
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
[truncated]�m\025b�K�YS�\023\035C�Lr\017�+�\005�r'�\u0086�\033�^w��څW~\a�<~O\021��b�:��\036)=\tP��$\004\177/�\005��c]|�\036�>���*�K�J\001�4�X\177Hipuz\036��y5��C
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
[truncated]\a�\016֯�\034�ez�qԶ=�\037��f0_x�\027N%�A�_��+<Uy�ɤb�I+-\032�qEG�\032�\037S���J\024�\002u_YA\037ʼnVͨ\036�{\v�Yiu���u+���g�7u^�%��MO;t\026�\006Ux�&k�يV
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
File Data: 214 bytes
Data (214 bytes)
Data: b899657c2cde44d0fbe8a3d4b526c691a6f8d417a8cdcb8fa78de5c12908177f899ec015…
[Length: 214]
Important Announcement:
CS Personal is taking a break