Wireshark Workbook – Lab 2

I’ll admit, Lab 1 took me longer than I’d hoped to complete, review, and write about. We had the Labor Day Weekend in the mix, so that’s my excuse.

I started work on Lab 2 earlier this week, having completed and reviewed them last night.

For me there were a couple of opportunities for some light reading. For example, while I know at a high level what Window Scale is or Maximum Segment Size (MSS), it was just that. High level. One of the questions I enjoyed was an open ended question asking to analyze the TCP handshake and explain the capabilities.

I wasn’t quite sure what the answer would be (turned out my answer was spot on), but it led me to read a little more deeply into MSS, Window Scale, and even a bit deeper into what SACK meant.

As I work through these labs and questions, I’m not simply trying to find the answer. I’m trying to understand both the answer and how I got there. I have very clear objectives in my mind as I go through this learning exercise. I want to be able to open a PCAP and spot problems, identify potential issues, and as some might say – tell the story.

The questions in this lab, as the image above show, talked about proxy servers. For one of the questions I was instantly stumped. It asked about a .pac file and what it was for. My notes / answer verbatim:

Something completely new to me. It’s always good to be learning new things.

The next lab and questions will deal with examining differences between HTTP and HTTPS. I’ve some familiarity with both of these at a high level, so again it will be fun to dive a little deeper into the weeds with a keen eye towards how I can take the information and use it later on.

Leave a Reply

Your email address will not be published. Required fields are marked *