lesson 18 wireshark capture analysis who shot my computer?

31
Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Upload: luella

Post on 12-Jan-2016

92 views

Category:

Documents


6 download

DESCRIPTION

Lesson 18 Wireshark Capture Analysis Who Shot My Computer?. Overview. System Information Network Information IO Analysis Significant Events. Tools Used. WireShark EtherApe SNORT Grey Matter. System Information. Host name: KAUFMANUPSTAIRS Time of Events: 3:30 - 3:38PM - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Lesson 18

Wireshark Capture Analysis

Who Shot My Computer?

Page 2: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Overview

• System Information

• Network Information

• IO Analysis

• Significant Events

Page 3: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Tools Used

• WireShark

• EtherApe

• SNORT

• Grey Matter

Page 4: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

System Information

• Host name: KAUFMANUPSTAIRS

• Time of Events: 3:30 - 3:38PM

• Number of Packets: 2449

• Total Bytes Captured: 811157

Page 5: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Analysis Summary

Page 6: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

EtherApe View

Page 7: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Input/Output Analysis

Page 8: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

IO Analysis 1

Page 9: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

IO Analysis 2

Page 10: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

DNS ResolutionWorkstation – 172.16.1.35 accesses DNS – 172.16.0.1

ARP (Address Resolution Protocol) resolves the MAC Address of: 00:40:ca:70:19:a3

Page 11: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Network Information

• Logical network

• External Connection

• Observed Protocols

Page 12: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Observed Network Addresses

• 172.16.0.1 – Gateway device– Homeportal.gateway.2wire.net

• 172.16.1.34

• 172.16.1.35 - TiVo Media Services

• 172.16.1.36

• 172.16.1.37

• 172.16.1.39

Page 13: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

IP Address Resolution 172.16.1.34, .36, .37, & .39 were made

No IP address was issued except for 172.16.1.35.

Page 14: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Gateway

wpad.gateway.2wire.net

Page 15: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Flow Analysis Internal

Page 16: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Endpoint Analysis-IPv4

Page 17: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Endpoint Analysis-TCP

Page 18: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Endpoint Analysis-UDP

Page 19: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

External Connections

• 216.166.24.20 – RBFCU.ORG

• 152.163.15.208 – America Online

Page 20: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Flow Analysis External

Page 21: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Protocols Observed

Page 22: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

HTTP Summary

Page 23: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

HTTP Details

Page 24: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Significant Events

• Packet 73 – Anonymous FTP• Packet 236 - HTTP• Packet 958 - HTTPS• Packet 1205 – Tivo• Packet 1591 – IPv6• Packets: 1788 (Yahoo)

2123(AOL) 2156 (AIM)

Page 25: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

FTPPacket 72-- FTP session was initiated with linux-wlan.org

Accessed using USER: anonymous, PSWD: IEUser@

Page 26: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

HTTP

• Packet 236: HTTP session initiated with www.rbfcu.org

Page 27: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

HTTPSPacket 958: HTTPS session initiated with

www.rbfcu.org (SSLv2 & SSLv3)

Page 28: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Tivo

Packet 1205: DVR

Page 29: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

IPv6 Packet 1591: a IPv6 Compaq Peer detected

Page 30: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

SNORT Analysis

Just Port Scans?

Page 31: Lesson 18 Wireshark Capture Analysis Who Shot My Computer?

Summary

• Do Analysis of the facts

• Make No Assumptions

• What Story Does it tell?

• Can you tell the story or do you need more facts?

• Can you get the facts?

• From Where?