CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 9282
from
2017-10-21-traffic-analysis-exercise.pcap
Follow HTTP
Follow TCP
Download as .txt
Frame 9282: 452 bytes on wire (3616 bits), 452 bytes captured (3616 bits)
Encapsulation type: Ethernet (1)
Arrival Time: Oct 21, 2017 05:02:49.707880000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1508562169.707880000 seconds
[Time delta from previous captured frame: 0.069878000 seconds]
[Time delta from previous displayed frame: 0.069878000 seconds]
[Time since reference or first frame: 656.394377000 seconds]
Frame Number: 9282
Frame Length: 452 bytes (3616 bits)
Capture Length: 452 bytes (3616 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:png]
Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 34.206.190.189, Dst: 10.0.1.95
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 438
Identification: 0x28de (10462)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 128
Protocol: TCP (6)
Header Checksum: 0x237a [validation disabled]
[Header checksum status: Unverified]
Source Address: 34.206.190.189
Destination Address: 10.0.1.95
[Source GeoIP: Ashburn, US, ASN 14618, AMAZON-AES]
[Source GeoIP City: Ashburn]
[Source or Destination GeoIP City: Ashburn]
[Source GeoIP Country: United States]
[Source or Destination GeoIP Country: United States]
[Source GeoIP ISO Two Letter Country Code: US]
[Source or Destination GeoIP ISO Two Letter Country Code: US]
[Source GeoIP AS Number: 14618]
[Source or Destination GeoIP AS Number: 14618]
[Source GeoIP AS Organization: AMAZON-AES]
[Source or Destination GeoIP AS Organization: AMAZON-AES]
[Source GeoIP Latitude: 39.0469]
[Source or Destination GeoIP Latitude: 39.0469]
[Source GeoIP Longitude: -77.4903]
[Source or Destination GeoIP Longitude: -77.4903]
Transmission Control Protocol, Src Port: 80, Dst Port: 61279, Seq: 1593, Ack: 5707, Len: 398
Source Port: 80
Destination Port: 61279
[Stream index: 244]
[Conversation completeness: Incomplete, DATA (15)]
[TCP Segment Len: 398]
Sequence Number: 1593 (relative sequence number)
Sequence Number (raw): 3236517264
[Next Sequence Number: 1991 (relative sequence number)]
Acknowledgment Number: 5707 (relative ack number)
Acknowledgment number (raw): 1443976470
0101 .... = Header Length: 20 bytes (5)
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······AP···]
Window: 64240
[Calculated window size: 64240]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x3f64 [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 20.173266000 seconds]
[Time since previous frame in this TCP stream: 0.069878000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.085613000 seconds]
[Bytes in flight: 398]
[Bytes sent since last PSH flag: 398]
TCP payload (398 bytes)
Hypertext Transfer Protocol
HTTP/1.1 200 OK\r\n
[Expert Info (Chat/Sequence): HTTP/1.1 200 OK\r\n]
[HTTP/1.1 200 OK\r\n]
[Severity level: Chat]
[Group: Sequence]
Response Version: HTTP/1.1
Status Code: 200
[Status Code Description: OK]
Response Phrase: OK
Date: Sat, 21 Oct 2017 05:02:51 GMT\r\n
Content-Type: image/gif\r\n
Transfer-Encoding: chunked\r\n
Connection: keep-alive\r\n
X-Powered-By: Express\r\n
Access-Control-Allow-Origin: *\r\n
Access-Control-Allow-Methods: GET,PUT,POST,DELETE\r\n
Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept\r\n
\r\n
[HTTP response 5/10]
[Time since request: 0.070103000 seconds]
[Prev request in frame: 9266]
[Prev response in frame: 9268]
[Request in frame: 9280]
[Next request in frame: 9286]
[Next response in frame: 9288]
[Request URI [truncated]: http://dt.clnmde.com/ptmd?t=%7B%22pet%22%3A56082%2C%22exInd%22%3A23%2C%22status%22%3A23%2C%22za%22%3A1%2C%22env%22%3A%22p%22%2C%22gh%22%3A%2215085621488801074183180%22%2C%22ts%22%3A%221429807462558%22%2C%22vs%22%3]
HTTP chunked response
Data chunk (70 octets)
Chunk size: 70 octets
Chunk data: 89504e470d0a1a0a0000000d49484452000000010000000108060000001f15c489000000…
Chunk boundary: 0d0a
End of chunked encoding
Chunk size: 0 octets
\r\n
File Data: 70 bytes
[Expert Info (Note/Malformed): HTTP body subdissector failed, trying heuristic subdissector]
[HTTP body subdissector failed, trying heuristic subdissector]
[Severity level: Note]
[Group: Malformed]
Portable Network Graphics
PNG Signature: 89504e470d0a1a0a
Image Header (IHDR)
Len: 13
Chunk: IHDR
..0. .... .... .... .... .... .... .... = Ancillary: This is a CRITICAL chunk
.... .... ..0. .... .... .... .... .... = Private: This is a PUBLIC chunk
.... .... .... .... .... .... ..0. .... = Safe To Copy: This chunk is NOT safe to copy
Width: 1
Height: 1
Bit Depth: 8
Colour Type: Truecolour with alpha (6)
Compression Method: Deflate (0)
Filter Method: Adaptive (0)
Interlace Method: No interlace (0)
CRC: 0x1f15c489
Image data chunk (IDAT)
Len: 13
Chunk: IDAT
..0. .... .... .... .... .... .... .... = Ancillary: This is a CRITICAL chunk
.... .... ..0. .... .... .... .... .... = Private: This is a PUBLIC chunk
.... .... .... .... .... .... ..0. .... = Safe To Copy: This chunk is NOT safe to copy
Data
CRC: 0x84a98c21
Image Trailer (IEND)
Len: 0
Chunk: IEND
..0. .... .... .... .... .... .... .... = Ancillary: This is a CRITICAL chunk
.... .... ..0. .... .... .... .... .... = Private: This is a PUBLIC chunk
.... .... .... .... .... .... ..0. .... = Safe To Copy: This chunk is NOT safe to copy
CRC: 0xae426082
Important Announcement:
CS Personal is taking a break