CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 8947
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 8947: 241 bytes on wire (1928 bits), 241 bytes captured (1928 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 05:02:31.799743000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508562151.799743000 seconds
[Time delta from previous captured frame: 0.000585000 seconds]
[Time delta from previous displayed frame: 0.000585000 seconds]
[Time since reference or first frame: 638.486240000 seconds]
Frame Number: 8947
Frame Length: 241 bytes (1928 bits)
Capture Length: 241 bytes (1928 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:ocsp]
Ethernet II, Src: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f), Dst: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Destination: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 10.0.1.95, Dst: 72.21.91.29
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 227
Identification: 0x4f62 (20322)
Flags: 0x40, Don't fragment
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0xfc21 [validation disabled]
[Header checksum status: Unverified]
Source Address: 10.0.1.95
Destination Address: 72.21.91.29
[Destination GeoIP: US, ASN 15133, EDGECAST]
[Destination GeoIP Country: United States]
[Source or Destination GeoIP Country: United States]
[Destination GeoIP ISO Two Letter Country Code: US]
[Source or Destination GeoIP ISO Two Letter Country Code: US]
[Destination GeoIP AS Number: 15133]
[Source or Destination GeoIP AS Number: 15133]
[Destination GeoIP AS Organization: EDGECAST]
[Source or Destination GeoIP AS Organization: EDGECAST]
[Destination GeoIP Latitude: 37.751]
[Source or Destination GeoIP Latitude: 37.751]
[Destination GeoIP Longitude: -97.822]
[Source or Destination GeoIP Longitude: -97.822]
Transmission Control Protocol, Src Port: 61323, Dst Port: 80, Seq: 1, Ack: 1, Len: 187
Source Port: 61323
Destination Port: 80
[Stream index: 288]
[Conversation completeness: Complete, WITH_DATA (31)]
[TCP Segment Len: 187]
Sequence Number: 1 (relative sequence number)
Sequence Number (raw): 1939820865
[Next Sequence Number: 188 (relative sequence number)]
Acknowledgment Number: 1 (relative ack number)
Acknowledgment number (raw): 2218346983
0101 .... = Header Length: 20 bytes (5)
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······AP···]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x16ce [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 0.070003000 seconds]
[Time since previous frame in this TCP stream: 0.018577000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.051426000 seconds]
[Bytes in flight: 187]
[Bytes sent since last PSH flag: 187]
TCP payload (187 bytes)
Hypertext Transfer Protocol
POST / HTTP/1.0\r\n
[Expert Info (Chat/Sequence): POST / HTTP/1.0\r\n]
[POST / HTTP/1.0\r\n]
[Severity level: Chat]
[Group: Sequence]
Request Method: POST
Request URI: /
Request Version: HTTP/1.0
Host: ocsp.digicert.com\r\n
Content-Type: application/ocsp-request\r\n
Content-Length: 83\r\n
[Content length: 83]
\r\n
[Full request URI: http://ocsp.digicert.com/]
[HTTP request 1/1]
[Response in frame: 8985]
File Data: 83 bytes
Online Certificate Status Protocol
tbsRequest
requestList: 1 item
Request
reqCert
hashAlgorithm (SHA-1)
Algorithm Id: 1.3.14.3.2.26 (SHA-1)
issuerNameHash: 105fa67a80089db5279f35ce830b43889ea3c70d
issuerKeyHash: 0f80611c823161d52f28e78d4638b42ce1c6d9e2
serialNumber: 0x0ec09224a7382d21fecc287f50ded5de
Important Announcement:
CS Personal is taking a break