CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 1865
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 1865: 875 bytes on wire (7000 bits), 875 bytes captured (7000 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 04:55:08.788219000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508561708.788219000 seconds
[Time delta from previous captured frame: 0.051117000 seconds]
[Time delta from previous displayed frame: 0.051117000 seconds]
[Time since reference or first frame: 195.474716000 seconds]
Frame Number: 1865
Frame Length: 875 bytes (7000 bits)
Capture Length: 875 bytes (7000 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:data-text-lines]
Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 13.107.4.52, Dst: 10.0.1.95
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 861
Identification: 0x0f09 (3849)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0x0b95 [validation disabled]
[Header checksum status: Unverified]
Source Address: 13.107.4.52
Destination Address: 10.0.1.95
[Source GeoIP: US, ASN 8068, MICROSOFT-CORP-MSN-AS-BLOCK]
[Source GeoIP Country: United States]
[Source or Destination GeoIP Country: United States]
[Source GeoIP ISO Two Letter Country Code: US]
[Source or Destination GeoIP ISO Two Letter Country Code: US]
[Source GeoIP AS Number: 8068]
[Source or Destination GeoIP AS Number: 8068]
[Source GeoIP AS Organization: MICROSOFT-CORP-MSN-AS-BLOCK]
[Source or Destination GeoIP AS Organization: MICROSOFT-CORP-MSN-AS-BLOCK]
[Source GeoIP Latitude: 37.751]
[Source or Destination GeoIP Latitude: 37.751]
[Source GeoIP Longitude: -97.822]
[Source or Destination GeoIP Longitude: -97.822]
Transmission Control Protocol, Src Port: 80, Dst Port: 53133, Seq: 1643, Ack: 265, Len: 821
Source Port: 80
Destination Port: 53133
[Stream index: 60]
[Conversation completeness: Complete, WITH_DATA (47)]
[TCP Segment Len: 821]
Sequence Number: 1643 (relative sequence number)
Sequence Number (raw): 3481131947
[Next Sequence Number: 2464 (relative sequence number)]
Acknowledgment Number: 265 (relative ack number)
Acknowledgment number (raw): 2779191617
0101 .... = Header Length: 20 bytes (5)
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······AP···]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xfdb9 [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 0.224926000 seconds]
[Time since previous frame in this TCP stream: 0.051117000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.047531000 seconds]
[Bytes in flight: 821]
[Bytes sent since last PSH flag: 821]
TCP payload (821 bytes)
Hypertext Transfer Protocol
HTTP/1.1 200 OK\r\n
[Expert Info (Chat/Sequence): HTTP/1.1 200 OK\r\n]
[HTTP/1.1 200 OK\r\n]
[Severity level: Chat]
[Group: Sequence]
Response Version: HTTP/1.1
Status Code: 200
[Status Code Description: OK]
Response Phrase: OK
Content-Length: 22\r\n
[Content length: 22]
Content-Type: text/plain\r\n
Content-MD5: BMP8SohYjuR9M9BmkgrEEA==\r\n
Last-Modified: Fri, 04 Mar 2016 06:55:03 GMT\r\n
ETag: "0x8D343F9E96C9DAC"\r\n
Server: Microsoft-IIS/7.5\r\n
x-ms-request-id: 37e7a986-001e-0029-6c46-34ffe6000000\r\n
x-ms-version: 2009-09-19\r\n
x-ms-meta-CbModifiedTime: Tue, 01 Mar 2016 21:41:22 GMT\r\n
x-ms-lease-status: unlocked\r\n
x-ms-blob-type: BlockBlob\r\n
X-ECN-P: RD0003FF837650\r\n
Access-Control-Expose-Headers: X-MSEdge-Ref\r\n
Access-Control-Allow-Origin: *\r\n
Timing-Allow-Origin: *\r\n
X-CID: 7\r\n
X-CCC: US\r\n
X-MSEdge-Ref: Ref A: E90A84223FB34B99A684B24D86B2AF7C Ref B: CHGEDGE0420 Ref C: 2017-10-21T04:55:10Z\r\n
X-MSEdge-Ref-OriginShield: Ref A: 0C42452BBDD04849AADE4F5BECE8406E Ref B: CH1EDGE0419 Ref C: 2017-10-14T16:11:55Z\r\n
Date: Sat, 21 Oct 2017 04:55:09 GMT\r\n
\r\n
[HTTP response 3/6]
[Time since request: 0.051235000 seconds]
[Prev request in frame: 1860]
[Prev response in frame: 1862]
[Request in frame: 1863]
[Next request in frame: 1867]
[Next response in frame: 1869]
[Request URI: http://www.msftconnecttest.com/connecttest.txt]
File Data: 22 bytes
Line-based text data: text/plain (1 lines)
Microsoft Connect Test
Important Announcement:
CS Personal is taking a break