Skip to content

Title Banner

Wireshark: The Basics Logo

Wireshark: The Basics

This guide contains the answer and steps necessary to get to them for the Wireshark: The Basics room.

Table of contents

Introduction

  1. Which file is used to simulate the screenshots?

Click for answerhttp1.pcapng

  1. Which file is used to answer the questions?

Click for answerExercise.pcapng

Tool Overview

Use the "Exercise.pcapng" file to answer the questions.

For these questions we must look at the Capture File Properties.

Overview Answers

  1. Read the "capture file comments". What is the flag?

Click for answerTryHackMe_Wireshark_Demo

  1. What is the total number of packets?

Click for answer58620

  1. What is the SHA256 hash value of the capture file?

Click for answerf446de335565fb0b0ee5e5a3266703c778b2f3dfad7efeaeccb2da5641a6d6eb

Packet Dissection

Use the "Exercise.pcapng" file to answer the questions.

  1. View packet number 38. Which markup language is used under the HTTP protocol?

After selecting the corresponding packet, the used markup language is displayed at the bottom of the details pane.

Dissection Markup

Click for answereXtensible Markup Language

  1. What is the arrival date of the packet? (Answer format: Month/Day/Year)

This can be found under the Frame layer.

Dissection Time

Click for answer05/13/2004

  1. What is the TTL value?

This can be found under the IP Source layer.

Dissection TTL

Click for answer47

  1. What is the TCP payload size?

This can be found under the TCP layer.

Dissection Payload

Click for answer424

  1. What is the e-tag value?

This can be found under the HTTP layer.

Dissection Etag

Click for answer9a01a-4696-7e354b00

Packet Navigation

Use the "Exercise.pcapng" file to answer the questions.

  1. Search the "r4w" string in packet details. What is the name of artist 1?

Searching for "r4w" in the packets details pane, we get a hit for packet 43362.

Navigation Artist

Click for answerr4w8173

  1. Go to packet 12 and read the comments. What is the answer?

Package 12 contains the following comment.

Go to packet number 39765
Look at the "packet details pane". Right-click on the JPEG section and "Export packet bytes". This is an alternative way of extracting data from a capture file. What is the MD5 hash value of extracted image?

Navigation Answer 1

After navigating to packet 39765 and exporting the object, we can extract its hash using md5sum.

Navigation Download

Navigation Hash

Click for answer911cd574a42865a956ccde2d04495ebf

  1. There is a ".txt" file inside the capture file. Find the file and read it; what is the alien's name?

To get this file, we navigate to the 'export http objects' menu. Here we filter on text/plain files. This gives us one hit. From here we can preview it to find the name.

Navigation Alien

Click for answerPacketmaster

  1. Look at the expert info section. What is the number of warnings?

The warning row has a column with the number of errors.

Navigation Warnings

Click for answer1636

Packet Filtering

Use the "Exercise.pcapng" file to answer the questions.

  1. Go to packet number 4. Right-click on the "Hypertext Transfer Protocol" and apply it as a filter. Now, look at the filter pane. What is the filter query?

After applying the filter, we see the query in the display filter box.

Filtering Http

Click for answerhttp

  1. What is the number of displayed packets?

At the bottom of the window we get the number of displayed packets.

Click for answer1089

  1. Go to packet number 33790 and follow the stream. What is the total number of artists?

After navigating to packet 33790 and following the http stream, we can see the entire communication stream. We can get the number of artist by looking at the stream or by exporting the relevant html file.

Filtering Follow

Filtering Artists

Click for answer3

  1. What is the name of the second artist?

Click for answerBlad3