{"id":238,"date":"2023-09-08T12:53:51","date_gmt":"2023-09-08T20:53:51","guid":{"rendered":"https:\/\/www.dumpsterfirecomputing.com\/?p=238"},"modified":"2023-09-08T12:55:48","modified_gmt":"2023-09-08T20:55:48","slug":"wireshark-workbook-lab-2","status":"publish","type":"post","link":"https:\/\/www.dumpsterfirecomputing.com\/?p=238","title":{"rendered":"Wireshark Workbook &#8211; Lab 2"},"content":{"rendered":"\n<p>I&#8217;ll admit, Lab 1 took me longer than I&#8217;d hoped to complete, review, and write about.  We had the Labor Day Weekend in the mix, so that&#8217;s my excuse.<\/p>\n\n\n\n<p>I started work on Lab 2 earlier this week, having completed and reviewed them last night.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.dumpsterfirecomputing.com\/wp-content\/uploads\/2023\/09\/image-2.png\" alt=\"\" class=\"wp-image-239\" style=\"width:293px;height:201px\" width=\"293\" height=\"201\" srcset=\"https:\/\/www.dumpsterfirecomputing.com\/wp-content\/uploads\/2023\/09\/image-2.png 622w, https:\/\/www.dumpsterfirecomputing.com\/wp-content\/uploads\/2023\/09\/image-2-300x206.png 300w\" sizes=\"auto, (max-width: 293px) 100vw, 293px\" \/><\/figure>\n\n\n\n<p>For me there were a couple of opportunities for some light reading.  For example, while I know at a high level what Window Scale is or Maximum Segment Size (MSS), it was just that.  High level.  One of the questions I enjoyed was an open ended question asking to analyze the TCP handshake and explain the capabilities.<\/p>\n\n\n\n<p>I wasn&#8217;t quite sure what the answer would be (turned out my answer was spot on), but it led me to read a little more deeply into <a href=\"https:\/\/en.wikipedia.org\/wiki\/Maximum_segment_size\">MSS<\/a>, <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc7323\">Window Scale<\/a>, and even a bit deeper into what <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc2018\">SACK <\/a>meant.<\/p>\n\n\n\n<p>As I work through these labs and questions, I&#8217;m not simply trying to find the answer.  I&#8217;m trying to <em>understand<\/em> both the answer and how I got there.  I have very clear objectives in my mind as I go through this learning exercise.  I want to be able to open a PCAP and spot problems, identify potential issues, and as some might say &#8211; tell the story.<\/p>\n\n\n\n<p>The questions in this lab, as the image above show, talked about proxy servers.  For one of the questions I was instantly stumped.  It asked about a <em>.pac<\/em> file and what it was for.  My notes \/ answer verbatim:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"747\" height=\"118\" src=\"https:\/\/www.dumpsterfirecomputing.com\/wp-content\/uploads\/2023\/09\/image-3.png\" alt=\"\" class=\"wp-image-240\" srcset=\"https:\/\/www.dumpsterfirecomputing.com\/wp-content\/uploads\/2023\/09\/image-3.png 747w, https:\/\/www.dumpsterfirecomputing.com\/wp-content\/uploads\/2023\/09\/image-3-300x47.png 300w\" sizes=\"auto, (max-width: 747px) 100vw, 747px\" \/><\/figure>\n\n\n\n<p>Something completely new to me.  It&#8217;s always good to be learning new things.<\/p>\n\n\n\n<p>The next lab and questions will deal with examining differences between HTTP and HTTPS.  I&#8217;ve some familiarity with both of these at a high level, so again it will be fun to dive a little deeper into the weeds with a keen eye towards how I can take the information and use it later on.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ll admit, Lab 1 took me longer than I&#8217;d hoped to complete, review, and write about. We had the Labor Day Weekend in the mix, so that&#8217;s my excuse. I [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[14,53],"class_list":["post-238","post","type-post","status-publish","format-standard","hentry","category-learning","tag-learning","tag-wireshark"],"_links":{"self":[{"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/posts\/238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=238"}],"version-history":[{"count":2,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/posts\/238\/revisions"}],"predecessor-version":[{"id":243,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/posts\/238\/revisions\/243"}],"wp:attachment":[{"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}