3. Packet Analysis
• Captured Network Traffic
• Analyze the protocols, carve out the files,
search for strings
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
4. Packet Analysis
• Analyze fileds within protocols
• Analyze Protocols within packets
• Analyze Packets within streams
• Reconstruct higher-layer protocols
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
5. Issue Found
• Too many stream packet
• Packet corrupted or truncated
• Contents encrypted at different layers
• Unstandard protocols
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
6. Protocol Analysis
• Examination of one or more fields within
the protocol’s data structure.
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
7. Packet Analysis
• Packet Analysis
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
8. WiresharkWorkshop
Network Packet Analysis Technical
(25 Oktober 2012)
Ahmad Muammar W.K. OSCP
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
9. WireShark
Advance Usage
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
10. Wireshark Display
• Packet List
• Packet Details
• Packet Bytes
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
11. Packet List
Packet List
Packet Details
Packet Bytes
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
12. Wireshark
Coloring Rules
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
25. Packet Analysis
Wrong Dissector
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
26. Protocol Dissector
• Allow Wireshark to automatically break
down into various section so that it can
be analyzed
• Translator, decoder
• Not work for non-standard/default port.
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
29. Wrong Dissector
• So its an SSL traffic
• But, why we able to see all info
• FTP Traffic using port 443?
• Decode it with FTP
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
33. Packet Analysis
Reconstruct File and Data
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
34. Reconstruct Data
• nc -lv 110 > confidential.pdf
• nc -vv 192.168.1.222 110 <
confidential.pdf
• non standard port send pdf and zip
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13
35. Packet Analysis
Reconstruct PDF File
Network Packet Analysis - Ahmad Muammar W.K. OSCP
Tuesday, January 22, 13