Download - Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Transcript
Page 1: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Lesson 18

Wireshark Capture Analysis

Who Shot My Computer?

Page 2: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Overview

• System Information

• Network Information

• IO Analysis

• Significant Events

Page 3: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Tools Used

• WireShark

• EtherApe

• SNORT

• Grey Matter

Page 4: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

System Information

• Host name: KAUFMANUPSTAIRS

• Time of Events: 3:30 - 3:38PM

• Number of Packets: 2449

• Total Bytes Captured: 811157

Page 5: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Analysis Summary

Page 6: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

EtherApe View

Page 7: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Input/Output Analysis

Page 8: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

IO Analysis 1

Page 9: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

IO Analysis 2

Page 10: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

DNS ResolutionWorkstation – 172.16.1.35 accesses DNS – 172.16.0.1

ARP (Address Resolution Protocol) resolves the MAC Address of: 00:40:ca:70:19:a3

Page 11: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Network Information

• Logical network

• External Connection

• Observed Protocols

Page 12: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Observed Network Addresses

• 172.16.0.1 – Gateway device– Homeportal.gateway.2wire.net

• 172.16.1.34

• 172.16.1.35 - TiVo Media Services

• 172.16.1.36

• 172.16.1.37

• 172.16.1.39

Page 13: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

IP Address Resolution 172.16.1.34, .36, .37, & .39 were made

No IP address was issued except for 172.16.1.35.

Page 14: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Gateway

wpad.gateway.2wire.net

Page 15: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Flow Analysis Internal

Page 16: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Endpoint Analysis-IPv4

Page 17: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Endpoint Analysis-TCP

Page 18: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Endpoint Analysis-UDP

Page 19: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

External Connections

• 216.166.24.20 – RBFCU.ORG

• 152.163.15.208 – America Online

Page 20: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Flow Analysis External

Page 21: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Protocols Observed

Page 22: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

HTTP Summary

Page 23: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

HTTP Details

Page 24: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Significant Events

• Packet 73 – Anonymous FTP• Packet 236 - HTTP• Packet 958 - HTTPS• Packet 1205 – Tivo• Packet 1591 – IPv6• Packets: 1788 (Yahoo)

2123(AOL) 2156 (AIM)

Page 25: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

FTPPacket 72-- FTP session was initiated with linux-wlan.org

Accessed using USER: anonymous, PSWD: IEUser@

Page 26: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

HTTP

• Packet 236: HTTP session initiated with www.rbfcu.org

Page 27: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

HTTPSPacket 958: HTTPS session initiated with

www.rbfcu.org (SSLv2 & SSLv3)

Page 28: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Tivo

Packet 1205: DVR

Page 29: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

IPv6 Packet 1591: a IPv6 Compaq Peer detected

Page 30: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

SNORT Analysis

Just Port Scans?

Page 31: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Summary

• Do Analysis of the facts

• Make No Assumptions

• What Story Does it tell?

• Can you tell the story or do you need more facts?

• Can you get the facts?

• From Where?