CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 5856
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 5856: 1282 bytes on wire (10256 bits), 1282 bytes captured (10256 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 05:02:05.729436000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508562125.729436000 seconds
[Time delta from previous captured frame: 0.253174000 seconds]
[Time delta from previous displayed frame: 0.253174000 seconds]
[Time since reference or first frame: 612.415933000 seconds]
Frame Number: 5856
Frame Length: 1282 bytes (10256 bits)
Capture Length: 1282 bytes (10256 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:data-text-lines]
Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 35.198.166.240, Dst: 10.0.1.95
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 1268
Identification: 0x1b4c (6988)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0x44a3 [validation disabled]
[Header checksum status: Unverified]
Source Address: 35.198.166.240
Destination Address: 10.0.1.95
[Source GeoIP: Frankfurt am Main, DE, ASN 396982, GOOGLE-CLOUD-PLATFORM]
[Source GeoIP City: Frankfurt am Main]
[Source or Destination GeoIP City: Frankfurt am Main]
[Source GeoIP Country: Germany]
[Source or Destination GeoIP Country: Germany]
[Source GeoIP ISO Two Letter Country Code: DE]
[Source or Destination GeoIP ISO Two Letter Country Code: DE]
[Source GeoIP AS Number: 396982]
[Source or Destination GeoIP AS Number: 396982]
[Source GeoIP AS Organization: GOOGLE-CLOUD-PLATFORM]
[Source or Destination GeoIP AS Organization: GOOGLE-CLOUD-PLATFORM]
[Source GeoIP Latitude: 50.1169]
[Source or Destination GeoIP Latitude: 50.1169]
[Source GeoIP Longitude: 8.6837]
[Source or Destination GeoIP Longitude: 8.6837]
Transmission Control Protocol, Src Port: 80, Dst Port: 61115, Seq: 1, Ack: 497, Len: 1228
Source Port: 80
Destination Port: 61115
[Stream index: 170]
[Conversation completeness: Complete, WITH_DATA (31)]
[TCP Segment Len: 1228]
Sequence Number: 1 (relative sequence number)
Sequence Number (raw): 427037397
[Next Sequence Number: 1229 (relative sequence number)]
Acknowledgment Number: 497 (relative ack number)
Acknowledgment number (raw): 4216854217
0101 .... = Header Length: 20 bytes (5)
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······AP···]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x435f [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 0.530606000 seconds]
[Time since previous frame in this TCP stream: 0.253174000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.207659000 seconds]
[Bytes in flight: 1228]
[Bytes sent since last PSH flag: 1228]
TCP payload (1228 bytes)
Hypertext Transfer Protocol
HTTP/1.0 200 OK\r\n
[Expert Info (Chat/Sequence): HTTP/1.0 200 OK\r\n]
[HTTP/1.0 200 OK\r\n]
[Severity level: Chat]
[Group: Sequence]
Response Version: HTTP/1.0
Status Code: 200
[Status Code Description: OK]
Response Phrase: OK
X-Powered-By: PHP/5.3.3\r\n
Content-type: text/html\r\n
Content-Length: 77248\r\n
[Content length: 77248]
Date: Sat, 21 Oct 2017 04:55:16 GMT\r\n
Server: lighttpd/1.4.45\r\n
\r\n
[HTTP response 1/1]
[Time since request: 0.253264000 seconds]
[Request in frame: 5854]
[Request URI: http://amellet.bit/html/]
File Data: 1074 bytes
Line-based text data: text/html (10 lines)
[truncated]��\032���7\b9��fD��4o�����\034���s8\036l���\036v;��5>\004��R%��S��-H�B�4�̻�[\000и�c]#��Hꢹ\002��\�[�h�_c�3\006'�g2&?�\f\t/ω\��Wl�
)'=<�\0262����nSVV\030���6Y\n
�Zև*aS��^�ج�\n
U2}bY;!;{r�=\031�$ו��?\a0���F��V\000�M�%\024\017���*\005�C���Z��1W�\004�G\b���(v>/��UN6\n
UZE|V\003\000��\a�͐�_�dP�\004]� �꺫QV&u{E�C 3�7RP\027�A�oȣ��\026��\030\005D@��K��\034|N��J\026j �cf�/\r
i�\r
[truncated]�\020�����#\v��)֟ؕ\003I\000��X�m��\a��B����z��I�}i��q\034y\b֑�\004u�e����\033�#��\t֜��XEX�P�۩R��� \v~\bkm���cÜyi��r���\u038D
�\a\027U\%U�q,�,�\017~\r
[truncated]x��b�v$Bx�\a(�E�J��\020\002��r�|2�ˁ~�Bc�\035�n�\020a`��\037d�W��<\000�}�O\004.�O<g��\026�O\022\030�3�}央Q�RqHB�.Іob1��Tg��5�h։I�>D>/�`��y�
��yl�E\0065�\024�'�(�h�n��\002n\0161�\b�*�.@�C*#�[$�.5&`j���Q���[��m?n
Important Announcement:
CS Personal is taking a break