CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 8874
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 8874: 779 bytes on wire (6232 bits), 779 bytes captured (6232 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 05:02:31.582648000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508562151.582648000 seconds
[Time delta from previous captured frame: 0.006021000 seconds]
[Time delta from previous displayed frame: 0.006021000 seconds]
[Time since reference or first frame: 638.269145000 seconds]
Frame Number: 8874
Frame Length: 779 bytes (6232 bits)
Capture Length: 779 bytes (6232 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:json:data-text-lines]
Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 173.241.244.212, Dst: 10.0.1.95
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 765
Identification: 0x27fb (10235)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0x61db [validation disabled]
[Header checksum status: Unverified]
Source Address: 173.241.244.212
Destination Address: 10.0.1.95
[Source GeoIP: Oak Brook, US]
[Source GeoIP City: Oak Brook]
[Source or Destination GeoIP City: Oak Brook]
[Source GeoIP Country: United States]
[Source or Destination GeoIP Country: United States]
[Source GeoIP ISO Two Letter Country Code: US]
[Source or Destination GeoIP ISO Two Letter Country Code: US]
[Source GeoIP Latitude: 41.829]
[Source or Destination GeoIP Latitude: 41.829]
[Source GeoIP Longitude: -87.9306]
[Source or Destination GeoIP Longitude: -87.9306]
Transmission Control Protocol, Src Port: 80, Dst Port: 61319, Seq: 17258, Ack: 894, Len: 725
Source Port: 80
Destination Port: 61319
[Stream index: 284]
[Conversation completeness: Complete, WITH_DATA (31)]
[TCP Segment Len: 725]
Sequence Number: 17258 (relative sequence number)
Sequence Number (raw): 78344636
[Next Sequence Number: 17983 (relative sequence number)]
Acknowledgment Number: 894 (relative ack number)
Acknowledgment number (raw): 868527684
0101 .... = Header Length: 20 bytes (5)
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······AP···]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xe78d [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 0.355239000 seconds]
[Time since previous frame in this TCP stream: 0.054387000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.050093000 seconds]
[Bytes in flight: 725]
[Bytes sent since last PSH flag: 725]
TCP payload (725 bytes)
Hypertext Transfer Protocol
HTTP/1.1 200 OK\r\n
[Expert Info (Chat/Sequence): HTTP/1.1 200 OK\r\n]
[HTTP/1.1 200 OK\r\n]
[Severity level: Chat]
[Group: Sequence]
Response Version: HTTP/1.1
Status Code: 200
[Status Code Description: OK]
Response Phrase: OK
Vary: Accept\r\n
Set-Cookie: i=5f9f07be-c0f3-4feb-8ddd-35a7fbfb7345|1508562149; Version=1; Expires=Sun, 21-Oct-2018 05:02:32 GMT; Max-Age=31536000; Domain=.openx.net; Path=/\r\n
Server: OXGW/11.136.0\r\n
Pragma: no-cache\r\n
P3P: CP="CUR ADM OUR NOR STA NID"\r\n
Expires: Mon, 26 Jul 1997 05:00:00 GMT\r\n
Date: Sat, 21 Oct 2017 05:02:32 GMT\r\n
Content-Type: application/json\r\n
Cache-Control: private, max-age=0, no-cache\r\n
Transfer-Encoding: chunked\r\n
Content-Encoding: gzip\r\n
\r\n
[HTTP response 2/2]
[Time since request: 0.054656000 seconds]
[Prev request in frame: 8791]
[Prev response in frame: 8812]
[Request in frame: 8853]
[Request URI: http://us-ads.openx.net/w/1.0/acj?o=9060646519&callback=OX_9060646519&ju=http%3A//www.singlemoms.org/&jr=&auid=537253288&dims=784x514&adxy=0%2C0&res=1024x768x24&plg=swf%2Cshk%2Cpm&ch=utf-8&tz=0&ws=0x0&ifr=1&tws=784x514]
HTTP chunked response
Data chunk (16 octets)
Chunk size: 16 octets
Chunk data: 1f8b080000000000040302000000ffff
Chunk boundary: 0d0a
Data chunk (219 octets)
Chunk size: 219 octets
Chunk data: 4d8fdd6ac4201085eff314e24569a18d9a46592d611fa1b7855282ab8604122371c2a604…
Chunk boundary: 0d0a
End of chunked encoding
Chunk size: 0 octets
\r\n
Content-encoded entity body (gzip): 235 bytes -> 288 bytes
File Data: 288 bytes
JavaScript Object Notation: application/json
Line-based text data: application/json (11 lines)
OX_9060646519({\n
"ads":{\n
"chain":1,\n
"medium":"w",\n
"record_tmpl":"http://us-ads.openx.net/{medium}/1.0/{rtype}?ts={txn_state}",\n
"pixels":"http://us-u.openx.net/w/1.0/pd?plm=10&ph=94ef58655625200a8cfc5b15afcd0b94ad52d590",\n
"oxt": 3.662,\n
"adunits" : [\n
]\n
}\n
});\n
Important Announcement:
CS Personal is taking a break