Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

1 . What was the first connection made, to where, and via what protocol? 1 5 : 4 0 : 1 9 . 5 7

1. What was the first connection made, to where, and via what protocol?
15:40:19.571032 IP 192.168.2.62.44389>192.168.2.104.22: S 1273007928:1273007928(0) win 5840
15:40:19.571720 IP 192.168.2.104.22>192.168.2.62.44389: S 1312754191:1312754191(0) ack 1273007929 win 5792
15:40:19.571812 IP 192.168.2.62.44389>192.168.2.104.22: . ack 1 win 92
15:40:19.604635 IP 192.168.2.104.22>192.168.2.62.44389: P 1:40(39) ack 1 win 91
15:40:19.611687 IP 192.168.2.62.44389>192.168.2.104.22: . ack 40 win 92
15:40:19.612844 IP 192.168.2.62.44389>192.168.2.104.22: P 1:40(39) ack 40 win 92
2. What website did the user visit? What port did it connect to?
15:42:31.063149 IP 192.168.2.62.36182>192.168.2.1.53: 64516+ A? google.com. (28)
15:42:31.080163 IP 192.168.2.1.53>192.168.2.62.36182: 645166/0/0 A 74.125.95.103,[|domain]
15:42:31.126128 IP 192.168.2.62.60175>74.125.95.103.80: S 3347203011:3347203011(0) win 5840
15:42:31.151658 IP 74.125.95.103.80>192.168.2.62.60175: S 1961428039:1961428039(0) ack 3347203012 win 5672
15:42:31.151923 IP 192.168.2.62.60175>74.125.95.103.80: . ack 1 win 92
15:42:31.152698 IP 192.168.2.62.60175>74.125.95.103.80: P 1:465(464) ack 1 win 92
15:42:31.185873 IP 74.125.95.103.80>192.168.2.62.60175: . ack 465 win 106
15:42:31.186930 IP 74.125.95.103.80>192.168.2.62.60175: P 1:512(511) ack 465 win 106
15:42:31.186969 IP 192.168.2.62.60175>74.125.95.103.80: . ack 512 win 108
3. What is different about this connection to the same site? Explain what was different, and what this would mean to a security analyst performing packet captures.
15:47:49.273824 IP 192.168.2.62.42937>192.168.2.1.53: 30382+ A? www.google.com. (32)
15:47:49.292587 IP 192.168.2.1.53>192.168.2.62.42937: 303827/0/0 CNAME www.l.google.com.,[|domain]
15:47:49.293736 IP 192.168.2.62.44190>209.85.225.104.443: S 4032272183:4032272183(0) win 5840
15:47:49.320776 IP 209.85.225.104.443>192.168.2.62.44190: S 901179054:901179054(0) ack 4032272184 win 5672
15:47:49.320842 IP 192.168.2.62.44190>209.85.225.104.443: . ack 1 win 92
15:47:49.321702 IP 192.168.2.62.44190>209.85.225.104.443: P 1:164(163) ack 1 win 92
15:47:49.351569 IP 209.85.225.104.443>192.168.2.62.44190: . ack 164 win 106
15:47:49.352940 IP 209.85.225.104.443>192.168.2.62.44190

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access with AI-Powered Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Students also viewed these Databases questions