Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Networking Support
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Networking Support General Networking Support Forum

Reply
 
Thread Tools
Old 05-09-2008, 09:56 AM   #1 (permalink)
Registered User
 
Join Date: May 2008
Posts: 3
OS: xp, ubuntu 7.10


ethereal/wireshark log analyze help

Hello, i would like to ask you guys / girls to help me a little. I got a Ethereal/WireShark log and i need to analyze it, but i can`t to do all...(today i see first time a log like this, dunno where i can start, or what mean very much thing in the log, the courses is more theoretical so don`t have much partice and the prof just added this homework, we don`t got any notice) Pls if somebody can help, or know a good site where i can learn what mean that things in the log file, or how to earn the data from that logfile pls tell me.... Thx again
here is some question....

* What DLL/MAC layer addresses can be seen in the trace?
* What IP addresses can be seen in the trace?
* How do the DLL/MAC and IP addresses map to each other?
* What is the Ethernet packet type and what does it mean?
* Can you tell from the trace file which Ethernet card is used to capture the traffic data, a normal 10/100M Ethernet card or an 802.11b wireless card?
* Can you deduce anything about the network topology on which this trace was taken, i.e. on which machine is the trace being taken? How many hosts are on the local network? What is the default gateway? What is the network mask? Which hosts are on the local network? Which ones are remote?
* How "far" away are the remote hosts?
* What different IP packet types can be seen what does each mean?
* Does IP fragmentation occur?
* Why would some packets have the "Don't fragment" bit set?
* Why the difference in the TTL values? If there was suddenly a change in the reported TTL, what would that be an indicator of?
* Are there any protocols that appear to be operating differently than as described in class?
* This packet trace is full of surprises, especially for someone who has never looked at a packet trace in detail before. List a few observations that were surprising to you including details of the observation and why it was particularly noteworthy.

There is the log file
http://www.filecrunch.com/fileDown [...] eId=145967
proview is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 05-09-2008, 11:43 AM   #2 (permalink)
Registered User
 
Join Date: May 2008
Posts: 3
OS: xp, ubuntu 7.10


Re: ethereal/wireshark log analyze help

i screwed up the link, sorry. here is the now link

http://www.filecrunch.com/fileDownlo...&fileId=145967

Last edited by proview : 05-09-2008 at 11:51 AM.
proview is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 05-09-2008, 12:26 PM   #3 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 27,300
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Re: ethereal/wireshark log analyze help

WOW! You're asking way too much for most folks to spend on a single issue here. It would take a long time to explain all of the in's and out's of the IP protocol! I suggest you do some basic research and ask targeted questions, don't take the shotgun approach.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 05-10-2008, 05:50 AM   #4 (permalink)
Registered User
 
Join Date: May 2008
Posts: 3
OS: xp, ubuntu 7.10


Re: ethereal/wireshark log analyze help

I made some basic search...
now i don`t know the answers for this questions..
my problem is i can`t read this form a logfile.. don`t see it, don`t know where i search it, or how i search....did to write out the IP, sort by IP but can`t figure out the answers for that questions.. pls somebody help me

* Can you deduce anything about the network topology on which this trace was taken, i.e. on which machine is the trace being taken? How many hosts are on the local network? What is the default gateway? What is the network mask? Which hosts are on the local network? Which ones are remote?
* How "far" away are the remote hosts?
* What different IP packet types can be seen what does each mean?
* This packet trace is full of surprises, especially for someone who has never looked at a packet trace in detail before. List a few observations that were surprising to you including details of the observation and why it was particularly noteworthy.
proview is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old Yesterday, 01:39 PM   #5 (permalink)
Registered User
 
Join Date: May 2008
Posts: 1
OS: xp


Re: ethereal/wireshark log analyze help

Howdy all. I'm the instructor this course.

First, thanks for recognizing that answering all of the questions doesn't really help the student.

Second, the assignment was posted a couple of weeks ago and is due June 4th so the student has plenty of time.

Third, if you are the student and are ready this, Brett (that's the TA for everyone else) was due to go over the homework in discussion Friday at 12pm.

Fourth, I have no problem asking general questions on a list like this (after all, when you got out into the real world, how else are you going to learn?), but try and answer questions on your own first.

And finally, if anyone else is reading this and is now curious about the context, here's the course web page:

http://www.cs.ucsb.edu/~almeroth/classes/S08.176A/

-Kevin
test_for_now is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 06:20 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81