Lab 4

Updated 4 Oct 2026

Part 2: Wireshark - GUI Packet Analyzer

What is Wireshark?

  • Open-source, cross-platform GUI tool
  • Provides detailed protocol breakdown
  • Color-coded packet display
  • Advanced filtering and analysis
  • Can save/import captures (.pcap files)

Starting Wireshark

sudo wireshark

⚠️ Important: Must use sudo for packet capture permissions


Wireshark GUI Components

The interface has 5 major parts:

1. Command Menu

  • Top menu bar: File, Edit, View, Go, Capture, Analyze, Statistics
  • Access to all functions

2. Display Filter Bar

  • Text field below menu
  • Enter filter expressions
  • Shows only packets matching criteria

3. Packet-Listing Window (Top Pane)

  • One-line summary per packet
  • Columns:
    • No.: Packet number
    • Time: Timestamp
    • Source: Source IP/MAC
    • Destination: Destination IP/MAC
    • Protocol: Protocol type
    • Length: Packet size (bytes)
    • Info: Summary information

4. Packet-Detail Window (Middle Pane)

  • Detailed protocol breakdown
  • Expandable tree structure
  • Shows all protocol layers:
    • Frame (physical layer)
    • Ethernet (data link layer)
    • IP (network layer)
    • TCP/UDP (transport layer)
    • Application data

5. Packet-Content Window (Bottom Pane)

  • Raw packet data
  • Two views:
    • Hexadecimal: Raw bytes
    • ASCII: Text representation

Analogy: These windows are like different zoom levels on a microscope - packet-listing shows many cells, packet-detail zooms into structure, packet-content shows the raw DNA.


Wireshark Workflow

Step-by-Step:

  1. Start Wireshark:

    sudo wireshark
  2. Select Interface:

    • Click "Capture Interfaces" icon (left side)
    • Choose eth0 (or your active NIC)
    • Click "Close"
  3. Generate Traffic:

  4. Start Capture:

    • Click "Start Capture" icon (shark fin/play button)
    • Watch packets appear in real-time
  5. Stop Capture:

    • Click "Stop Capture" icon (red square)
  6. Save Capture (Optional):

    • File → Save As
    • Choose .pcap or .pcapng format

Wireshark Color Coding

Wireshark uses colors to identify packet types quickly.

Common Colors:

ColorPacket Type
Light PurpleTCP traffic
Light BlueUDP traffic
Light GreenHTTP traffic
YellowICMP traffic (ping)
BlackTCP packets with problems/errors
Light PinkICMP errors
Dark GrayTCP retransmissions

View All Color Rules:

  • Menu: View → Coloring Rules

Tip: Customize colors in Preferences if default scheme doesn't work for you


Part 3: Display Filters in Wireshark

What are Display Filters?

  • Show only packets matching specific criteria
  • Don't delete other packets (just hide them)
  • Applied after capture
  • Different from capture filters

Operators

Comparison Operators

OperatorMeaningExample
==Equal toip.src==192.168.1.1
!=Not equal toip.src!=192.168.1.1
>Greater thanframe.len>1000
>=Greater than or equalframe.len>=500
<Less thanframe.len<100
<=Less than or equalframe.len<=1500

Logical Operators

OperatorMeaningExample
&& or andBoth conditions true (AND)tcp && ip.src==192.168.1.1
| or orEither condition true (OR)icmp || arp
! or notCondition is false (NOT)!tcp

IP Address Filtering

Filter Types:

FilterDescriptionExample
ip.addrPackets to/from this IPip.addr==192.168.1.100
ip.srcPackets FROM this sourceip.src==192.168.1.100
ip.dstPackets TO this destinationip.dst==8.8.8.8

Examples:

# Show all traffic to/from specific IP
ip.addr==203.131.212.198

# Show packets FROM specific source
ip.src==192.168.1.100

# Show packets TO specific destination
ip.dst==8.8.8.8

# Combine: packets FROM 192.168.1.1 OR TO 8.8.8.8
ip.src==192.168.1.1 || ip.dst==8.8.8.8

# Packets between two IPs
ip.addr==192.168.1.1 && ip.addr==192.168.1.2

Protocol Filtering

Common Protocol Filters:

FilterDescription
arpShow only ARP packets
icmpShow only ICMP packets (ping)
tcpShow only TCP packets
udpShow only UDP packets
httpShow only HTTP traffic
httpsShow only HTTPS traffic
dnsShow only DNS queries/responses
sshShow only SSH traffic

Examples:

# Show only TCP traffic
tcp

# Show only ping packets
icmp

# Show only ARP requests
arp

# Show HTTP or HTTPS
http || https

# Show TCP on specific port
tcp.port==80

# Show DNS queries
dns

Port Filtering

# Specific port (either source or destination)
tcp.port==80

# Source port
tcp.srcport==443

# Destination port
tcp.dstport==22

# Port range
tcp.port>=1000 && tcp.port<=2000

Frame Length Filtering

# Packets smaller than 1000 bytes
frame.len < 1000

# Packets larger than 500 bytes
frame.len > 500

# Packets between 500-1500 bytes
frame.len > 500 && frame.len < 1500

# Exactly 1500 bytes
frame.len == 1500

Hostname Filtering

# Specific hostname
http.host == www.tu.ac.th

# Contains keyword
http.host contains "google"

# Multiple hostnames
http.host == www.siit.tu.ac.th || http.host == www.tu.ac.th

Part 4: Analyzing Ping with Wireshark

The Ping Process

When you ping a new IP address (not in ARP cache):

Step-by-Step Sequence:

  1. ARP Request (Broadcast)

    • Your computer → ALL computers on network
    • "Who has IP 192.168.1.50? Tell 192.168.1.100"
    • Destination MAC: ff:ff:ff:ff:ff:ff (broadcast)
  2. ARP Reply (Unicast)

    • Target computer → Your computer
    • "I have 192.168.1.50, my MAC is aa:bb:cc:dd:ee:ff"
    • Now your computer knows the MAC address
  3. ICMP Echo Request #1

    • Your computer → Target
    • "Ping!" (Are you there?)
  4. ICMP Echo Reply #1

    • Target → Your computer
    • "Pong!" (Yes, I'm here!)
  5. Steps 3-4 repeat for each ping packet


Why ARP Happens First

The Problem:

  • You only know the IP address (e.g., 192.168.1.50)
  • To send packets on local network, you need the MAC address
  • ARP resolves: IP address → MAC address

The Solution:

  • Send ARP broadcast asking "Who has this IP?"
  • Target replies with its MAC address
  • MAC address stored in ARP cache
  • ICMP packets can now be sent directly

Analogy: At a party, you want to find "Bob" (IP address) but don't know what he looks like (MAC address). You shout "WHERE'S BOB?" (broadcast ARP). Bob says "I'm Bob, wearing a red shirt!" (ARP reply). Now you can walk directly to Bob (send ICMP).


Analyzing Ping in Wireshark

Setup:

  1. Check ARP cache BEFORE ping:

    arp -n
  2. Ping new IP (not in cache):

    ping -c 5 192.168.1.50
  3. Check ARP cache AFTER ping:

    arp -n
    • IP 192.168.1.50 should now be in cache!
  4. Filter in Wireshark:

    arp || icmp
    

Expected Wireshark Output

Packet Sequence:

No. Time       Source          Destination     Protocol  Info
1   0.000000   192.168.1.100   Broadcast       ARP       Who has 192.168.1.50? Tell 192.168.1.100
2   0.001234   192.168.1.50    192.168.1.100   ARP       192.168.1.50 is at aa:bb:cc:dd:ee:ff
3   0.002000   192.168.1.100   192.168.1.50    ICMP      Echo (ping) request  id=0x1234, seq=1
4   0.003000   192.168.1.50    192.168.1.100   ICMP      Echo (ping) reply    id=0x1234, seq=1
5   1.002000   192.168.1.100   192.168.1.50    ICMP      Echo (ping) request  id=0x1234, seq=2
6   1.003000   192.168.1.50    192.168.1.100   ICMP      Echo (ping) reply    id=0x1234, seq=2
... (continues for 5 packets)

Key Observations:

  • Packets 1-2: ARP exchange (only happens once!)
  • Packets 3-4: First ping (ICMP echo request/reply)
  • Packets 5-6: Second ping
  • Pattern: No more ARP after first exchange

Ping to Cached IP (No ARP)

If IP is ALREADY in ARP cache:

# Check cache
arp -n  # 192.168.1.50 is already here
 
# Ping
ping -c 5 192.168.1.50
 
# Filter
arp || icmp

Expected Result:

  • NO ARP packets appear
  • ONLY ICMP packets visible
  • Why? MAC address already known!

Wireshark Output:

No. Time       Source          Destination     Protocol  Info
1   0.000000   192.168.1.100   192.168.1.50    ICMP      Echo request
2   0.001000   192.168.1.50    192.168.1.100   ICMP      Echo reply
3   1.000000   192.168.1.100   192.168.1.50    ICMP      Echo request
4   1.001000   192.168.1.50    192.168.1.100   ICMP      Echo reply
... (no ARP packets!)

Packet Details Breakdown

ARP Request Packet:

Frame:
  - Destination MAC: ff:ff:ff:ff:ff:ff (Broadcast)
  - Source MAC: [Your MAC]
Ethernet II:
  - Type: ARP (0x0806)
ARP:
  - Opcode: Request (1)
  - Sender MAC: [Your MAC]
  - Sender IP: 192.168.1.100
  - Target MAC: 00:00:00:00:00:00
  - Target IP: 192.168.1.50

ARP Reply Packet:

Frame:
  - Destination MAC: [Your MAC]
  - Source MAC: aa:bb:cc:dd:ee:ff
Ethernet II:
  - Type: ARP (0x0806)
ARP:
  - Opcode: Reply (2)
  - Sender MAC: aa:bb:cc:dd:ee:ff
  - Sender IP: 192.168.1.50
  - Target MAC: [Your MAC]
  - Target IP: 192.168.1.100

ICMP Echo Request:

Frame:
  - Destination MAC: aa:bb:cc:dd:ee:ff
  - Source MAC: [Your MAC]
Ethernet II:
  - Type: IPv4 (0x0800)
Internet Protocol:
  - Source: 192.168.1.100
  - Destination: 192.168.1.50
  - Protocol: ICMP (1)
ICMP:
  - Type: 8 (Echo request)
  - Code: 0
  - Identifier: 0x1234
  - Sequence: 1
  - Data: [56 bytes]

ICMP Echo Reply:

ICMP:
  - Type: 0 (Echo reply)
  - Code: 0
  - Identifier: 0x1234
  - Sequence: 1
  - Data: [56 bytes]

Protocol Reference

Common Protocols

ProtocolLayerPortDescription
ARP2 (Data Link)N/AAddress resolution (IP→MAC)
ICMP3 (Network)N/APing, error messages
TCP4 (Transport)VariousReliable, connection-oriented
UDP4 (Transport)VariousUnreliable, connectionless
HTTP7 (Application)80Web traffic (unencrypted)
HTTPS7 (Application)443Web traffic (encrypted)
DNS7 (Application)53Domain name resolution
SSH7 (Application)22Secure shell
FTP7 (Application)21File transfer
SMTP7 (Application)25Email sending

ICMP Types

TypeCodeDescription
00Echo Reply (ping response)
3-Destination Unreachable
30Network Unreachable
31Host Unreachable
33Port Unreachable
80Echo Request (ping)
110Time Exceeded (TTL=0)

TCP Flags

FlagMeaning
[S]SYN - Synchronize (start connection)
[.]ACK - Acknowledgment
[P]PSH - Push (send data immediately)
[F]FIN - Finish (close connection)
[R]RST - Reset (abort connection)
[S.]SYN+ACK (handshake response)