CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 7488
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 7488: 1514 bytes on wire (12112 bits), 1514 bytes captured (12112 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 05:02:28.435371000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508562148.435371000 seconds
[Time delta from previous captured frame: 0.000998000 seconds]
[Time delta from previous displayed frame: 0.000998000 seconds]
[Time since reference or first frame: 635.121868000 seconds]
Frame Number: 7488
Frame Length: 1514 bytes (12112 bits)
Capture Length: 1514 bytes (12112 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:ocsp:ocsp:x509sat:x509sat:x509sat:x509sat:x509ce:ocsp:x509ce:x509ce:x509ce:x509ce:x509sat]
Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 23.61.187.27, Dst: 10.0.1.95
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 1500
Identification: 0x24b4 (9396)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0x32b1 [validation disabled]
[Header checksum status: Unverified]
Source Address: 23.61.187.27
Destination Address: 10.0.1.95
[Source GeoIP: Mount Prospect, US, ASN 16625, AKAMAI-AS]
[Source GeoIP City: Mount Prospect]
[Source or Destination GeoIP City: Mount Prospect]
[Source GeoIP Country: United States]
[Source or Destination GeoIP Country: United States]
[Source GeoIP ISO Two Letter Country Code: US]
[Source or Destination GeoIP ISO Two Letter Country Code: US]
[Source GeoIP AS Number: 16625]
[Source or Destination GeoIP AS Number: 16625]
[Source GeoIP AS Organization: AKAMAI-AS]
[Source or Destination GeoIP AS Organization: AKAMAI-AS]
[Source GeoIP Latitude: 42.0648]
[Source or Destination GeoIP Latitude: 42.0648]
[Source GeoIP Longitude: -87.9356]
[Source or Destination GeoIP Longitude: -87.9356]
Transmission Control Protocol, Src Port: 80, Dst Port: 61267, Seq: 1, Ack: 227, Len: 1460
Source Port: 80
Destination Port: 61267
[Stream index: 232]
[Conversation completeness: Incomplete, DATA (15)]
[TCP Segment Len: 1460]
Sequence Number: 1 (relative sequence number)
Sequence Number (raw): 1677321165
[Next Sequence Number: 1461 (relative sequence number)]
Acknowledgment Number: 227 (relative ack number)
Acknowledgment number (raw): 159572568
0101 .... = Header Length: 20 bytes (5)
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······A····]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x2b38 [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 0.089863000 seconds]
[Time since previous frame in this TCP stream: 0.045811000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.042993000 seconds]
[Bytes in flight: 1460]
[Bytes sent since last PSH flag: 1460]
TCP payload (1460 bytes)
Hypertext Transfer Protocol
HTTP/1.1 200 OK\r\n
[Expert Info (Chat/Sequence): HTTP/1.1 200 OK\r\n]
[HTTP/1.1 200 OK\r\n]
[Severity level: Chat]
[Group: Sequence]
Response Version: HTTP/1.1
Status Code: 200
[Status Code Description: OK]
Response Phrase: OK
Server: nginx/1.10.2\r\n
Content-Type: application/ocsp-response\r\n
Content-Length: 1390\r\n
[Content length: 1390]
content-transfer-encoding: binary\r\n
Cache-Control: max-age=547981, public, no-transform, must-revalidate\r\n
Last-Modified: Fri, 20 Oct 2017 13:14:26 GMT\r\n
Expires: Fri, 27 Oct 2017 13:14:26 GMT\r\n
Date: Sat, 21 Oct 2017 05:02:29 GMT\r\n
Connection: keep-alive\r\n
\r\n
[HTTP response 1/1]
[Time since request: 0.045934000 seconds]
[Request in frame: 7346]
[Request URI: http://g.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACEAEAISWIsPpZp3fvBXtmJ98%3D]
File Data: 1104 bytes
Online Certificate Status Protocol
responseStatus: successful (0)
responseBytes
ResponseType Id: 1.3.6.1.5.5.7.48.1.1 (id-pkix-ocsp-basic)
BasicOCSPResponse
tbsResponseData
responderID: byKey (2)
byKey: 56e4542753e6aca97181dd86221e9ae47a72c42a
producedAt: 2017-10-20 13:14:26 (UTC)
responses: 1 item
SingleResponse
certID
hashAlgorithm (SHA-1)
Algorithm Id: 1.3.14.3.2.26 (SHA-1)
issuerNameHash: b1b439179016b797795011f160b9d4a23cdbedee
issuerKeyHash: 00f92ac34191b6c9c2b83e55f2c0971113a00720
serialNumber: 0x0100212588b0fa59a777ef057b6627df
certStatus: good (0)
good
thisUpdate: 2017-10-20 13:14:26 (UTC)
nextUpdate: 2017-10-27 13:14:26 (UTC)
signatureAlgorithm (sha1WithRSAEncryption)
Algorithm Id: 1.2.840.113549.1.1.5 (sha1WithRSAEncryption)
Padding: 0
signature: 3f1edfa6c863ad17341dcc87f89b2ffa1a9f5c551a4fa02c6a5f0ce6ab1a762f1c275022…
certs: 1 item
Certificate (id-at-commonName=GeoTrust Global CA TGV OCSP Responder 5)
signedCertificate
version: v3 (2)
serialNumber: 0x0100008f1c2b9615f579b9185e0ec267
signature (sha256WithRSAEncryption)
Algorithm Id: 1.2.840.113549.1.1.11 (sha256WithRSAEncryption)
issuer: rdnSequence (0)
rdnSequence: 3 items (id-at-commonName=GeoTrust Global CA,id-at-organizationName=GeoTrust Inc.,id-at-countryName=US)
RDNSequence item: 1 item (id-at-countryName=US)
RelativeDistinguishedName item (id-at-countryName=US)
Object Id: 2.5.4.6 (id-at-countryName)
CountryName: US
RDNSequence item: 1 item (id-at-organizationName=GeoTrust Inc.)
RelativeDistinguishedName item (id-at-organizationName=GeoTrust Inc.)
Object Id: 2.5.4.10 (id-at-organizationName)
DirectoryString: printableString (1)
printableString: GeoTrust Inc.
RDNSequence item: 1 item (id-at-commonName=GeoTrust Global CA)
RelativeDistinguishedName item (id-at-commonName=GeoTrust Global CA)
Object Id: 2.5.4.3 (id-at-commonName)
DirectoryString: printableString (1)
printableString: GeoTrust Global CA
validity
notBefore: utcTime (0)
utcTime: 2016-12-08 11:25:35 (UTC)
notAfter: utcTime (0)
utcTime: 2017-12-14 11:25:35 (UTC)
subject: rdnSequence (0)
rdnSequence: 1 item (id-at-commonName=GeoTrust Global CA TGV OCSP Responder 5)
RDNSequence item: 1 item (id-at-commonName=GeoTrust Global CA TGV OCSP Responder 5)
RelativeDistinguishedName item (id-at-commonName=GeoTrust Global CA TGV OCSP Responder 5)
Object Id: 2.5.4.3 (id-at-commonName)
DirectoryString: printableString (1)
printableString: GeoTrust Global CA TGV OCSP Responder 5
subjectPublicKeyInfo
algorithm (rsaEncryption)
Algorithm Id: 1.2.840.113549.1.1.1 (rsaEncryption)
subjectPublicKey: 3082010a0282010100a6ecc7bd9ec789530890f2de21c0cb8ef32ce074df3f04b9c48364…
modulus: 0x00a6ecc7bd9ec789530890f2de21c0cb8ef32ce074df3f04b9c48364840c8e4d40e5a65f…
publicExponent: 65537
extensions: 6 items
Extension (id-ce-authorityKeyIdentifier)
Extension Id: 2.5.29.35 (id-ce-authorityKeyIdentifier)
AuthorityKeyIdentifier
keyIdentifier: c07a98688d89fbab05640c117daa7d65b8cacc4e
Extension (id-pkix-ocsp-nocheck)
Extension Id: 1.3.6.1.5.5.7.48.1.5 (id-pkix-ocsp-nocheck)
NULL
Extension (id-ce-extKeyUsage)
Extension Id: 2.5.29.37 (id-ce-extKeyUsage)
KeyPurposeIDs: 1 item
KeyPurposeId: 1.3.6.1.5.5.7.3.9 (OCSPSigning)
Extension (id-ce-keyUsage)
Extension Id: 2.5.29.15 (id-ce-keyUsage)
critical: True
Padding: 7
KeyUsage: 80
1... .... = digitalSignature: True
.0.. .... = contentCommitment: False
..0. .... = keyEncipherment: False
...0 .... = dataEncipherment: False
.... 0... = keyAgreement: False
.... .0.. = keyCertSign: False
.... ..0. = cRLSign: False
.... ...0 = encipherOnly: False
0... .... = decipherOnly: False
Extension (id-ce-basicConstraints)
Extension Id: 2.5.29.19 (id-ce-basicConstraints)
critical: True
BasicConstraintsSyntax [0 length]
Extension (id-ce-subjectAltName)
Extension Id: 2.5.29.17 (id-ce-subjectAltName)
GeneralNames: 1 item
GeneralName: directoryName (4)
directoryName: rdnSequence (0)
rdnSequence: 1 item (id-at-commonName=)
RDNSequence item: 1 item (id-at-commonName=)
RelativeDistinguishedName item (id-at-commonName=)
Object Id: 2.5.4.3 (id-at-commonName)
DirectoryString: printableString (1)
printableString:
[BoundError Unreassembled Packet: OCSP]
Important Announcement:
CS Personal is taking a break