Network Security Lab
Wireshark: Seeing What the Network Sees
Wireshark is the world's most popular packet analyser. It captures traffic from a network interface (or opens a saved .pcap file) and shows every packet in detail. Network engineers use it to fix problems, and security analysts use it to investigate attacks.
In this lab you will work with a simulated capture from a small office network. No real traffic is captured. Your job is to act as an analyst and find four things hidden in the data.
Legal note: Only capture traffic on networks you own or have written permission to monitor. Capturing other people's traffic without permission is illegal in many places, including under Nigeria's Cybercrimes Act 2015.
The Wireshark Window
| Pane | What it shows |
|---|---|
| Packet list (top) | One row per packet: number, time, source, destination, protocol, length, info |
| Packet details (bottom left) | The packet unpacked layer by layer: Ethernet, IP, TCP or UDP, application |
| Packet bytes (bottom right) | The raw data in hex and ASCII |
| Display filter bar | Narrow the list to what matters |
Colours help: in real Wireshark, TCP, DNS, HTTP and ARP each have their own colour, and packets with problems are highlighted.
Display Filters You Should Know
| Filter | Shows |
|---|---|
dns | DNS queries and answers |
http | Web traffic in clear text |
ftp | FTP commands, including logins |
arp | Address resolution packets |
ip.addr == 192.168.1.66 | Everything to or from one host |
tcp.port == 23 | Traffic on a given port (here, Telnet) |
tcp.flags.syn == 1 | New connection attempts (SYN packets) |
frame contains "PASS" | Packets whose data includes some text |
You can combine them with && (and) and || (or). For example: ip.addr == 192.168.1.66 && tcp.flags.syn == 1.
Follow TCP Stream rebuilds a whole conversation in reading order. It is the fastest way to see exactly what was said in a clear-text session.
What Attacks Look Like in a Capture
- Phishing / DNS oddities: a lookup for a lookalike domain such as
bank-verify-login.comfollowed by a connection to an unfamiliar IP. - Clear-text credentials: FTP, Telnet and HTTP forms show usernames and passwords right in the packet data.
- ARP poisoning: two different MAC addresses claiming the same IP, and Wireshark warning duplicate use of x.x.x.x detected.
- Port scan: one source sending many SYN packets to many different ports in a short time. Open ports answer with SYN-ACK and closed ones with RST.
These are the same attacks you studied in the networking lessons, now seen from the defender's chair.
Your Mission
Use the lab on the right. Apply filters, click packets, and use Follow stream. Answer the four questions at the bottom.
- Which lookalike domain did
192.168.1.24look up? (Hint: try thednsfilter.) - What FTP password was sent in clear text? (Hint:
ftporframe contains "PASS", then Follow stream.) - Which MAC address is falsely claiming to be the gateway
192.168.1.1? (Hint:arp, and compare the two replies.) - Which IP address is port-scanning
192.168.1.50? (Hint:tcp.flags.syn == 1, and see who sends to many ports.)
After the Lab: Write Your Findings
A good analyst does not stop at "I found it". For each finding write:
- What you saw (the evidence: packet numbers and filters).
- Why it matters (impact).
- What to do (recommendation).
Example: Packets 17 and 19 show an FTP login in clear text (user tunde). Anyone on the network can capture it. Replace FTP with SFTP, and change the password now. You will use this same structure in penetration test reports in Module 6.
Continue Practising
Install Wireshark free from wireshark.org and try the sample captures on the Wireshark wiki, or the malware-traffic-analysis.net exercises. TryHackMe and Blue Team Labs Online have guided packet analysis rooms.
Try it yourself
Key Takeaways
- Wireshark captures and dissects packets. The packet list, details and bytes panes show the same data at different levels.
- Display filters (dns, http, ftp, arp, ip.addr, tcp.port, tcp.flags.syn == 1, frame contains) turn thousands of packets into the few that matter.
- Follow TCP Stream rebuilds a conversation and instantly exposes clear-text credentials on FTP, Telnet and HTTP.
- Common attack signatures: lookalike DNS lookups, duplicate ARP replies for one IP, and many SYNs to many ports from one host.
- Record findings as what, why it matters and what to do, and only capture traffic on networks you are authorised to monitor.
Quick Quiz
1.Which display filter shows only new connection attempts (SYN packets), useful for spotting a port scan?
2.In a capture, two different MAC addresses both answer that they own 192.168.1.1. What does this suggest?
3.Why is FTP a security problem that Wireshark makes obvious?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx