{"id":244,"date":"2023-09-11T12:58:16","date_gmt":"2023-09-11T20:58:16","guid":{"rendered":"https:\/\/www.dumpsterfirecomputing.com\/?p=244"},"modified":"2023-09-11T12:58:17","modified_gmt":"2023-09-11T20:58:17","slug":"wireshark-workbook-lab-3","status":"publish","type":"post","link":"https:\/\/www.dumpsterfirecomputing.com\/?p=244","title":{"rendered":"Wireshark Workbook &#8211; Lab 3"},"content":{"rendered":"\n<p>Lab 3 involved looking at some HTTP vs HTTPS data.  Another shorter lab that I managed to get done late Friday before the weekend got underway.  <\/p>\n\n\n\n<p>The labs and their questions are having me dig deeper into the filters and their syntax, and I&#8217;m learning that that&#8217;s where the power of Wireshark really lies.  These sample PCAP&#8217;s that we&#8217;re analyzing are pretty small, making manual scrolling through them pretty easy, but I can imagine larger PCAP&#8217;s where the only way to get at any useful information is through filters.  The trick, I suppose, is knowing what it is you&#8217;re looking for.<\/p>\n\n\n\n<p>The other thing I learned specifically was how to build and use the IO Graph.  Much to my surprise, it works in a somewhat similar way to the Windows Performance Monitor.  Instead of selecting from a pre-existing list of counters, you simply add a display filter and off you go.  In these questions I graphed the bits per second between HTTP and HTTPS traffic to find which one had the highest bps (no spoilers here &#8211; go get your own copy).<\/p>\n\n\n\n<p>As a small tangent &#8212; I don&#8217;t know why, but I seemed to have forgotten picking up one of Laura Chappell&#8217;s other books last year.  <a href=\"https:\/\/www.amazon.com\/Wireshark-101-Essential-Analysis-Solution\/dp\/1893939758\/ref=sr_1_1?crid=2NQHCGF80RW5X&amp;keywords=wireshark+101&amp;qid=1694465049&amp;sprefix=wireshark+101%2Caps%2C197&amp;sr=8-1\">Wireshark 101, Essential Skills for Network Analysis<\/a>.  I&#8217;m sad I forgot about that, but I now have it next to me and will be trying to get a little bit of that read after each lab as well.  When I really want to deep dive or understand something, I&#8217;ll whip out another tome on the shelf &#8211; <a href=\"https:\/\/www.amazon.com\/TCP-Illustrated-Protocols-Addison-Wesley-Professional\/dp\/0321336313\/ref=sr_1_1?crid=2SU0XY93TZNJU&amp;keywords=tcp%2Fip+illustrated+volume+1&amp;qid=1694465122&amp;sprefix=tcp%2Fip+%2Caps%2C192&amp;sr=8-1&amp;ufe=app_do%3Aamzn1.fos.18ed3cb5-28d5-4975-8bc7-93deae8f9840\">TCP\/IP Illustrated, Volume 1<\/a>.<\/p>\n\n\n\n<p>I know &#8211; all of the information contained in these books can be found online with a quick Bing search.  There&#8217;s just something I enjoy about having certain reference material in hardcopy.  Perhaps I&#8217;m old school.<\/p>\n\n\n\n<p>And with Lab 3 now behind me, I&#8217;m looking forward and starting in on Lab 4 &#8211; &#8220;TCP Analysis&#8221;.  I&#8217;ve a fairly busy week ahead of me but should be plenty of time to get it done.  There are a total of 16 labs in this book, and while I&#8217;m not looking to rush through it, my goal is to be complete before the Thanksgiving Holiday.  Leave the last month or so for thinking ahead to 2024&#8230;.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lab 3 involved looking at some HTTP vs HTTPS data. Another shorter lab that I managed to get done late Friday before the weekend got underway. The labs and their [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[14,53],"class_list":["post-244","post","type-post","status-publish","format-standard","hentry","category-learning","tag-learning","tag-wireshark"],"_links":{"self":[{"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/posts\/244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=244"}],"version-history":[{"count":1,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/posts\/244\/revisions"}],"predecessor-version":[{"id":245,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=\/wp\/v2\/posts\/244\/revisions\/245"}],"wp:attachment":[{"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dumpsterfirecomputing.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}