CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 8363
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 8363: 341 bytes on wire (2728 bits), 341 bytes captured (2728 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 05:02:30.144699000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508562150.144699000 seconds
[Time delta from previous captured frame: 0.002292000 seconds]
[Time delta from previous displayed frame: 0.002292000 seconds]
[Time since reference or first frame: 636.831196000 seconds]
Frame Number: 8363
Frame Length: 341 bytes (2728 bits)
Capture Length: 341 bytes (2728 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:image-gif]
Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 23.56.3.183, Dst: 10.0.1.95
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 327
Identification: 0x26cc (9932)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0xec97 [validation disabled]
[Header checksum status: Unverified]
Source Address: 23.56.3.183
Destination Address: 10.0.1.95
[Source GeoIP: San Jose, US, ASN 20940, Akamai International B.V.]
[Source GeoIP City: San Jose]
[Source or Destination GeoIP City: San Jose]
[Source GeoIP Country: United States]
[Source or Destination GeoIP Country: United States]
[Source GeoIP ISO Two Letter Country Code: US]
[Source or Destination GeoIP ISO Two Letter Country Code: US]
[Source GeoIP AS Number: 20940]
[Source or Destination GeoIP AS Number: 20940]
[Source GeoIP AS Organization: Akamai International B.V.]
[Source or Destination GeoIP AS Organization: Akamai International B.V.]
[Source GeoIP Latitude: 37.3388]
[Source or Destination GeoIP Latitude: 37.3388]
[Source GeoIP Longitude: -121.8916]
[Source or Destination GeoIP Longitude: -121.8916]
Transmission Control Protocol, Src Port: 80, Dst Port: 61293, Seq: 1, Ack: 580, Len: 287
Source Port: 80
Destination Port: 61293
[Stream index: 258]
[Conversation completeness: Incomplete, DATA (15)]
[TCP Segment Len: 287]
Sequence Number: 1 (relative sequence number)
Sequence Number (raw): 443086246
[Next Sequence Number: 288 (relative sequence number)]
Acknowledgment Number: 580 (relative ack number)
Acknowledgment number (raw): 1322836386
0101 .... = Header Length: 20 bytes (5)
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······AP···]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xbf34 [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 0.158090000 seconds]
[Time since previous frame in this TCP stream: 0.101014000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.056533000 seconds]
[Bytes in flight: 287]
[Bytes sent since last PSH flag: 287]
TCP payload (287 bytes)
Hypertext Transfer Protocol
HTTP/1.1 200 OK\r\n
[Expert Info (Chat/Sequence): HTTP/1.1 200 OK\r\n]
[HTTP/1.1 200 OK\r\n]
[Severity level: Chat]
[Group: Sequence]
Response Version: HTTP/1.1
Status Code: 200
[Status Code Description: OK]
Response Phrase: OK
Server: nginx\r\n
Content-Type: image/gif\r\n
Content-Length: 43\r\n
[Content length: 43]
Expires: Sat, 21 Oct 2017 05:02:31 GMT\r\n
Cache-Control: max-age=0, no-cache, no-store\r\n
Pragma: no-cache\r\n
Date: Sat, 21 Oct 2017 05:02:31 GMT\r\n
Connection: keep-alive\r\n
\r\n
[HTTP response 1/1]
[Time since request: 0.101140000 seconds]
[Request in frame: 8253]
[Request URI: http://opt-east.media.net/rtbs/pixel?key=4%3A%3A20171021%3A%3A05%3A%3AUS%3A%3A10.6.3.2_7017&value=3000&bid=4&country=US&cid=8CU1YR6V3&crid=576157511&domain=singlemoms.org&size=300x600&buyerid=null]
File Data: 43 bytes
Compuserve GIF, Version: GIF89a
Version: GIF89a
Screen width: 1
Screen height: 1
Global settings: (Global color table present) (1 bit per color) (1 bit per pixel)
1... .... = Global color map is present: True (1)
.000 .... = Bits per color minus 1: 0
.... 0... = Global color map is ordered: False (0)
.... .000 = Image bits per pixel minus 1: 0
Background color index: 0
Global color map: dbdfef000000
Extension: Graphics Control
Extension label: Graphics Control (0xf9)
Data block: 01000000 (length = 4)
Data block: <none> (length = 0)
Image
Image left position: 0
Image top position: 0
Image width: 1
Image height: 1
Local settings: (1 bit per color) (1 bit per pixel)
0... .... = Local color map is present: False (0)
.000 .... = Bits per color minus 1: 0
.... 0... = Local color map is ordered: False (0)
.... .000 = Image bits per pixel minus 1: 0
LZW minimum code size: 2
Data block: 4401 (length = 2)
Data block: <none> (length = 0)
Trailer (End of the GIF stream)
Important Announcement:
CS Personal is taking a break