CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 6622
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 6622: 1074 bytes on wire (8592 bits), 1074 bytes captured (8592 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 05:02:27.697091000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508562147.697091000 seconds
[Time delta from previous captured frame: 0.000006000 seconds]
[Time delta from previous displayed frame: 0.000006000 seconds]
[Time since reference or first frame: 634.383588000 seconds]
Frame Number: 6622
Frame Length: 1074 bytes (8592 bits)
Capture Length: 1074 bytes (8592 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:data]
Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 104.16.23.35, Dst: 10.0.1.95
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 1060
Identification: 0x22b4 (8884)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0x898e [validation disabled]
[Header checksum status: Unverified]
Source Address: 104.16.23.35
Destination Address: 10.0.1.95
[Source GeoIP: ASN 13335, CLOUDFLARENET]
[Source GeoIP AS Number: 13335]
[Source or Destination GeoIP AS Number: 13335]
[Source GeoIP AS Organization: CLOUDFLARENET]
[Source or Destination GeoIP AS Organization: CLOUDFLARENET]
Transmission Control Protocol, Src Port: 80, Dst Port: 61216, Seq: 56021, Ack: 308, Len: 1020
Source Port: 80
Destination Port: 61216
[Stream index: 181]
[Conversation completeness: Complete, WITH_DATA (31)]
[TCP Segment Len: 1020]
Sequence Number: 56021 (relative sequence number)
Sequence Number (raw): 310713187
[Next Sequence Number: 57041 (relative sequence number)]
Acknowledgment Number: 308 (relative ack number)
Acknowledgment number (raw): 2431537222
0101 .... = Header Length: 20 bytes (5)
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······AP···]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xd2f1 [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 0.252718000 seconds]
[Time since previous frame in this TCP stream: 0.000006000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.053409000 seconds]
[Bytes in flight: 2480]
[Bytes sent since last PSH flag: 2480]
TCP payload (1020 bytes)
Hypertext Transfer Protocol
[truncated]=�d{�u\005\036i-\017�S�.OJ�����8\a6\017��h�c�}o5�[���U̅n�3�\036`5�#��CzTI���ż\034��NF}�l1������\016�0��\a]XM�U\036���\025ъ�1l�\t<|Y'b�n
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
�B�+�0t|��،Opi��6�pSb�:5к�\027\fp.�G�U��<��\U0009D30F\177A\0336��<\177X���\0216�ͺK�-\036�U��]��l{8���8�r�\020\001b��[0y"�\0202�VDb�>\020�\027]:\0021�\r
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
File Data: 554 bytes
Data (554 bytes)
Data: cc8927b00c6c25981f44210d15028ea76dc29f2e413e5fbf72e71acd0e50ba6eeac31c7d…
[Length: 554]
Important Announcement:
CS Personal is taking a break