Overview
Join Erik Choron as he covers critical components of preventive cybersecurity through concepts of TCP/IP.
Supplemental File
Concepts of TCP/IP
Welcome back as we dive into another skill together. I’ve missed you.
Knowledge Check
In its raw form, data is transferred across the network in which of the following formats?
Part of the Bigger Picture
TCP/IP is only one part of the network packet when we take a look at what’s going across the wire.
Knowledge Check
Which parts of the data packet did we cover in this nugget?
Different parts of TCP/IP
So we have our basic understanding of TCP/IP down. Let’s move into different aspects of how it’s used inside of the network packet.
Knowledge Check
Which tool did we use to capture our packets in the terminal?
Were do we Get These Packets From?
Now we’ve seen some examples of breaking a packet down and looking into it a bit. But as we hinted in the last Nugget, these have to come from somewhere.
Knowledge Check
Packet capturing can be done in GUI and CLI form. True or false?
Replay the Traffic
What happens if we’ve recorded the traffic but need to replay it?
Knowledge Check
Which tool did we use to replay the traffic we captured?
Learning Binary and Hex
Now don’t worry, because this isn’t something we have to memorize. But we do need to get familiar with it and learn the basics.
Knowledge Check
What is the decimal value of 10010011?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Concepts of TCP/IP
0:00[AUDIO LOGO]
0:05First officer's log.
0:07Star date, something with numbers.
0:10I wonder what it is we could actually start getting
0:13into here in this next course.
0:16It's time for you to get into the packet
0:18and see what the user is actually doing.
0:20But I don't think that--
0:22Do it.
0:23Do it.
0:24Well, OK, if you insist.
0:26Welcome back as we dive into another course here together.
0:29I've missed you.
0:31And in this course, we're actually
0:32going to start looking at the actual data in the packets
0:35going across the wire between point A and point B.
0:38And we're talking about looking at the actual binary, hex,
0:42and all that other stuff.
0:44But fret ye not, fellow learner.
0:46We're actually going to break this down in such a way
0:49to where we don't have to really memorize
0:50a lot of hex and binary.
0:51We just want to get familiar with what's actually going on
0:54and so we can actually go in and take a look at the packet
0:57as it's broken down in programs like Wireshark, tcpdump,
1:01and whatever other programs that we
1:02use to be able to go in and analyze this traffic.
1:06Now, there are many different reasons.
1:07And we'll be going throughout this entire course,
1:09talking about why we'd want to do something like this.
1:12Part number one is we want to make sure
1:14that whatever it is that we're doing
1:17is in line with the security policy of the organization.
1:20So let's say we're trying to analyze why a firewall rule was
1:24put into place and it wasn't executed correctly.
1:27Somebody was able to get past it.
1:29Somebody was able to get around whatever the protocols were
1:34to block said traffic.
1:35Well, that's where network monitoring and going
1:38into wire analysis helps us in analyzing
1:42that kind of information, because if we're
1:44taking a look at the actual packet,
1:45we might find something that's inside of it.
1:48Maybe it's data that's wrapped around or wrapped
1:51in something else that it's not supposed to be.
1:54Let's say we're passing normal traffic to a website,
1:57but it's wrapped inside of a DNS packet
1:59and made to look like a DNS query.
2:02Now, we'll figure out later on how to actually start going in
2:04and do some of this.
2:05But that's kind of some of the stuff
2:07that we are looking forward to in this entire course.
2:10And for those playing at home, I actually did fix the lighting.
2:13I wanted to start off with the original
2:14and let you all know that I am taking
2:17key notes of your comments.
2:18And I appreciate that.
2:20Keep them coming.
2:20Let me know what content you want to see
2:22and what we need to cover as far as the cybersecurity
2:24and getting into the pen testing realm that we need to get into.
2:27I just want you to know that I really
2:29appreciate each and every one of you
2:30out there, along with the other courses here on CBT Nuggets.
2:35Without what we have here across the entire spectrum of CBT
2:39Nuggets, courses like this would be
2:41kind of not making a lot of sense.
2:44And that's why I also want to push out
2:46in this one, before we get started with the entire course,
2:49that there are many other programs
2:50and courses and certification tests
2:52here on CBT Nuggets that will help us out
2:55throughout the entirety of this course.
2:57So if for a moment, let's say, we
2:59need to understand a little bit more of the OSI model,
3:02get a little familiar with basic networking and some
3:05of the ideas that are going along with security overall,
3:08take a pause.
3:09Go look at some of the other courses.
3:11And meet me back over here because I'm not going anywhere.
3:13I'm here waiting for you.
3:15And it's completely OK because I too
3:17go across all the different courses here on CBT Nuggets
3:20to try to better myself.
3:21And it's really helped out a lot.
3:22So thank you to all the trainers as well
3:24and those behind the scenes at CBT Nuggets.
3:26[LIPS SMACKING]
3:27Now, in the grand scheme of things,
3:29this course right here is part 3 of our ongoing cybersecurity
3:33and pen testing slash hacking slash
3:35staying within the law series that we've been doing here
3:38together.
3:38And at first, we learned how to do security practices
3:41because we want to make sure everything's secure.
3:43The second course we did, which was pen testing and hacking
3:47and making sure that we understood the tools,
3:49was to test out those security controls.
3:51And in this course, we're going to be diving deeper into how
3:55we test out those security protocols because remember,
3:58we can't really implement security
4:00unless we know what it is that breaks that security
4:03to better defend against it.
4:05Now, throughout this skill right here, we're
4:07going to be taking a look at the overall picture of TCP/IP
4:10and getting more familiar and more acquainted with it,
4:13to make sure that we understand later on, when we start looking
4:15at raw packets, how it plays a bigger part in network
4:18and cybersecurity.
4:19We're going to be going over the different parts of TCP/IP
4:22because it's not just TCP.
4:24There's also its lesser known sibling, UDP,
4:27because we've moved away from UDP packets.
4:30But they still exist in critical environments.
4:33Then we're going to start taking a look at where we actually
4:35get these packets from and what it is that we're
4:37using to analyze them.
4:39Now, some of these tools may be familiar
4:40from our previous courses.
4:42But if you're new here, strap in,
4:44fire up those virtual machines, and get ready
4:46because this course is primarily going to be
4:48on our Kali virtual machine.
4:50I definitely encourage you to go back and take a look at some
4:52of the other courses that we've done here
4:54covering virtual machine, VirtualBox,
4:57and also how to use some of those virtual machines
5:00in a very basic setting because throughout this course,
5:03we'll definitely be using it, as we
5:04don't want to brick this system right here.
5:06That's where we do all of our recording at.
5:08But then we're going to be wrapping this skill up
5:10with binary and hex and actually going through and taking
5:13a look at what some of these packets actually look like
5:15and understanding that there is a rhyme and a reason to why
5:20things go across the wire the way they do.
5:22Now, diving straight into it, after our grand intro
5:27that we just did-- and welcome back,
5:28everybody-- that we need to understand
5:30that packets don't actually go over
5:32the wire in ASCII or letters.
5:35That's something that we as humans
5:38need to identify with because we understand our language as it
5:42is in front of us.
5:43How data actually transfers from one place to another
5:46is ones and zeros.
5:47And those ones and zeros in their different forms
5:51basically all come together and give us a rhythmic pattern,
5:55mathematically, which we won't dive too deep into, to tell us
5:59this is what it actually means.
6:00So if you're a fan of Futurama, I highly
6:02encourage, definitely go back and check out some of the ones
6:05where they make fun of binary, especially when a two pops up
6:08out of nowhere, because all those numbers are actually
6:11real.
6:11And they do equal out to actual words.
6:14Now, it may come as a shock to you,
6:15as I have here on the screen, a packet.
6:17And this is something that was pulled
6:19from Wireshark, which we'll be diving into later
6:21on in this course.
6:22But the first example that I have here on the screen
6:25is a packet dump-- one individual packet
6:28that was dumped out in hex format
6:30by default values inside of Wireshark.
6:33Now, it may surprise you here in this next one
6:35that this is the exact same packet in hex,
6:38except we lose all the spacing and the line numbers
6:42at the beginning of the format.
6:43And again, this is the same packet
6:47in a different type of hex value.
6:49And this right here is the same packet in binary.
6:53Now, all this translates to a packet
6:55that is understandable by computer
6:57systems across the network.
6:59We rely on our IDS and IPS, or Intrusion Detection
7:04or Intrusion Protection Systems, whether they
7:06be host based or network based, to be
7:08able to read this kind of traffic right
7:09here in a real-time environment, to make sure
7:13that we are actively and properly defending
7:16or implementing rules based on whatever the policy is
7:19for our organization.
7:20Now, I know that's a lot to take in.
7:22But don't worry.
7:22We're going to be walking through this step by step
7:24as we go out through the entirety of this course.
7:26And we're going to do it one skill at a time.
7:29So join me.
7:30Grab your VMs.
7:31Make sure they're still fired up,
7:33like we mentioned while ago.
7:34And let's do it to it.
Part of the Bigger Picture
0:01[AUDIO LOGO]
0:06TCP/IP is only one part of the network packet
0:08when we take a look at what's actually going on
0:10across the wire, and that's because when
0:13we put all the pieces of the puzzle together,
0:15TCP/IP is the overall storyline, if you will,
0:20of what's actually going on inside of a packet
0:22that we capture and analyze for whatever reason
0:25we need to analyze it for.
0:27Think of this like a box within a box.
0:29Well, IP packets or actual data packets that go across the wire
0:34because they may not be IP as we'll find out later on.
0:37All packets start off in a big, old box,
0:41and then inside of that box is another box that
0:44has the actual, let's say, the idea
0:47of what's actually going on.
0:48So the outside box is the overall data
0:51itself going from point A to point B,
0:53and the second box inside starts to tell us more
0:56of what's actually going on.
0:58Well, the more boxes we go in--
1:00what are those little Russian dolls
1:02that always open up and stuff like that?
1:04James would know.
1:05Definitely check out some of his Nuggets.
1:07But if we start taking a look at some of those inside boxes,
1:10the more deeper we go, the more information we get about what's
1:13actually inside that payload of the overall box itself
1:17because looking at the box on the outside just says,
1:19it's a box.
1:20And if we only go one deep, well, it's only one box.
1:23Now, it's two, and we don't really know that much.
1:25That's why we have to go in as much as possible.
1:27Now, before going too far deep into this course overall,
1:30you may notice that there is some supplemental material
1:33attached to this skill that we'll
1:35be using throughout the course, and I
1:37will try to remember to attach it to whatever skills
1:40in the future where we heavily rely on this documentation.
1:43But just in case, here in this skill,
1:46there will be a zip file that contains a PDF
1:48that I built when I was originally
1:50going through this course and learning about it myself.
1:53And you'll notice that there's a lot of different types
1:55of packet headers and translation tables
1:59going from hex to binary, to decimal, et cetera, et cetera.
2:04And we'll be going through those one by one
2:06as we go out through this entire course together.
2:09So don't be overwhelmed by it.
2:10Just know that it's here for you if you need it and want
2:13to use it whenever you're studying
2:15if there were an exam for this course overall.
2:18Now, let's get straight to it.
2:19TCP/IP is the Transmission Control Protocol
2:23and slash Internet Protocol.
2:26That is what is packaging everything
2:28inside of that second or third box
2:30that we were taking a look at.
2:32We're going to take a look at a demonstration packet
2:34here in a second and understand that TCP/IP is not actually
2:38the outer box.
2:39It's more of like the second or third one.
2:41The actual overall box itself is the entire data packet
2:44that we've captured for analysis.
2:46And then once we start digging in,
2:48we'll notice that it's more familiar in that TCP/IP setup.
2:52But let's take a look at the models
2:55and how they represent to each other from OSI to IPv4 to IPv6.
3:00And the reason we're doing this is,
3:01is because as prevalent as IPv6 is starting
3:04to get on the internet overall, we
3:06need to be familiar with that one
3:08as well, too, because that is under that TCP/IP protocol
3:12series.
3:12Now, looking at our models here, we
3:14can see where we go with as far as what's our physical, what's
3:19our actual network, transport, and application level
3:22because we can see that layers 5, 6, and 7 on the OSI model
3:27translate to applications on TCP/IP
3:30and what's actually happening on the series.
3:33Now, for TCP/IP, this is for IPv4 and IPv6.
3:38Please keep that in mind.
3:39Now, transport is the same all the way across,
3:42and we're talking about the actual segments.
3:44So this would be what we can call
3:46the payload of the actual data packet that we're capturing.
3:50So think of like the last tail end of what's
3:52actually going on here.
3:54What we're actually getting is the data
3:57that's being sent back and forth and not just
4:00to and from addressing.
4:01That's actually what we see in layer 3 of what's
4:04going on of the OSI model and the internet layer of TCP/IP.
4:10This is where we're going to be getting the to and from,
4:12source or destination IP addresses,
4:15whether they be IPv4 or IPv6, and also
4:18the ports that are being used.
4:20So if it's TCP, it'll be TCP port, whatever,
4:24on the destination and sourced out of whatever on our end.
4:27Same for UDP.
4:28And we'll see a little bit of discrepancies but the same idea
4:32when we get into stuff like ICMP and whatnot.
4:35And then layer 2 is our data link.
4:37And you'll notice on here that data link and physical are
4:40the same color and because under TCP/IP model,
4:43we have network access.
4:45This is our physical how are we hooking up stuff.
4:47And looking in the actual packet itself,
4:51when we see it here in a second, this is the out-of-the-box
4:54of what's actually going on.
4:55Now, I know what you're thinking.
4:57Where's this example that we're going to have?
4:58So here it is on screen.
5:00Now, this is a snippet out of Wireshark,
5:02and what we're taking a look at is
5:03how the Wireshark takes a look at some of these packets.
5:06We'll be getting deeper into Wireshark in a little bit.
5:08But on the outermost shell of a packet that we get,
5:12we have the frame, and this is going to tell us just some
5:16of the very basic stuff that's actually going on inside
5:19of that packet itself.
5:21So how big is it?
5:24What was the actual payload overall?
5:26And it'll tell us what interface ID that it came on
5:29as far as how it was captured.
5:31If we're doing this as a local capture,
5:33we're going to see that maybe this was picked up
5:36over Ethernet 0 as a default. Let's say, inside
5:39of our Kali VM.
5:40That's fine.
5:41But what we're taking a look for is,
5:44what's the overall size of the frame overall?
5:47So this could vary in size based on the type of protocol
5:51and versioning that's being used for this actual packet.
5:53Now, the next box inside of the frame is Ethernet II.
5:57And going back to our OSI reference model
6:00previously earlier in this video,
6:03you'll see that this kind of lines
6:05up with layer 2 of the OSI model and layer 1 of TCP/IP.
6:10This is where we're getting our information as far
6:13as MAC address, something physical.
6:15What's the actual physical address
6:17of the device that's sending and receiving this packet?
6:20So think of this as to and from addressing on the frame
6:24overall itself and maybe a packaging
6:27label on the inside box of something
6:29that we're sending through the mail.
6:31Now, there's a box inside of that one, too,
6:33and that is the IP version.
6:35This is where we start getting into layer 3
6:37on the OSI model and internet layer on the actual TCP/IP
6:42model.
6:42The networking portion of this for IP version
6:45tells us what IP addresses we're sending this to and from.
6:48So we're past that physical layer of MAC addresses
6:51and something on the local network,
6:53and we're actually having to go out and reach out and touch
6:55somebody that's not on our local network.
6:58Think of it like this.
6:59If it has to go past your gateway that's local
7:02there to be able to go out and reach something else,
7:05let's say, like the Google, then it's
7:07going to utilize layer 3 of the OSI model
7:09to be able to get to where it's going
7:11and the internet layer of the TCP/IP model.
7:14Now, if you're playing along at home--
7:16and we'll go back to this in a second.
7:18This is byte offset 0, and I'll get to cover this here
7:21in just a second.
7:22The box inside of that one is our IP protocol,
7:25and that is byte offset 9, and this
7:28is where we start getting into figuring out
7:30whether it's TCP, UDP, ICMP, or et cetera, et cetera.
7:34And this is layer 4 on this transport
7:37layer for OSI and TCP/IP.
7:40This is where we start getting into what it is exactly
7:43that we're expecting inside of the box inside of this one
7:46because again, this is a box within a box-type stuff here,
7:50and each layer that we pull off gives us
7:53more information of what's actually
7:55inside of the actual payload.
7:57And then we have the actual payload itself,
8:00which is byte offset 32.
8:02And again, we'll come back in a second.
8:03And the payload is where we actually
8:05start getting the data.
8:06So as an example, let's say that the packet that we're
8:10looking at here on the screen, and this
8:12was the example in the previous video when
8:14we were doing the hex dumps and everything,
8:16this is a packet that I just pulled off of Wireshark
8:20to run it real quick to get our hex dump,
8:22and we have in our frame that the packet is 95 bytes.
8:26Our Ethernet II source is the VMware VM MAC address
8:30of the actual VM itself.
8:32The IP protocol version that we're having here is version 6.
8:36So you can see, we're starting to go up
8:38the layers in the OSI model.
8:40And then this one was a UDP protocol.
8:44And so the payload on this will be
8:47the next part, which is the Multicast Domain Name system.
8:51And what that means is, is that the UDP protocol is identifying
8:57that it's sending out a payload that's aligned
9:00to the actual Multicast DNS.
9:03And so it's sensing out on the network what exactly is my name
9:07and what are other names on the network.
9:09Who else is out there that I can be friends with?
9:11Now, if you're looking at the supplemental material
9:13that we put up in this skill that we're
9:15going to be using throughout the entirety of this course,
9:18the first one we're taking a look at here is page 2,
9:21and this is the IPv4 header.
9:23And this is where I was mentioning
9:24a while ago the offset bytes and stuff
9:27like that because up until now, it probably didn't
9:30make any sense, and that's OK.
9:31So when we go and compare this to our OSI model,
9:35our TCP/IP model for layers and whatnot,
9:39that's where all this starts really coming together
9:41when we analyze a packet in this course.
9:44The frame is the overall what you see here
9:47on page 2 for the IPv4 header.
9:50Now, we're picking on IPv4, and I'll show you IPv6 in a second.
9:54It's not too far different.
9:56The Ethernet II frame, which is the second box inside,
10:00is going to be our version and our first half of byte
10:05offset 0.
10:06So it's going to tell us really what kind of IP
10:09are we expected to get.
10:11In the next box is our IP version, which
10:13is the second half of byte offset 0, and it tells us,
10:17are we using IPv4 or IPv6?
10:19And then we have our IP protocol,
10:21which, if you look on the next line in orange byte offset 9,
10:25it says protocol 8-bit.
10:27And I have on here also key guides
10:29to let us know what it is that we're using.
10:32And if you're really starting to put the pieces together,
10:34the hex is actually answered in the keys that I have below.
10:38Then in the packet example that we had previously,
10:41we're using UDP.
10:42So in this IP protocol byte offset 9 area,
10:46you would actually see in hex 0x11, which gives us UDP.
10:53And so in that packet, you would start
10:55to see somewhere in there.
10:57I'll let you look at home, but you'll
10:59start to see where 0x11 translated to actual hex
11:03itself.
11:04And this is stuff we'll get into in a little bit in the course,
11:08but you can break down where it's actually turning into hex.
11:11So just to hint hint, it's probably
11:1314 echo 9 if you're looking back at the earlier packet.
11:17Now, the actual payload starts at byte offset 32.
11:20That is line 5, where it says data variable.
11:23And the reason that is, is because data can be
11:25whatever size it needs to be.
11:28We're not going to send an entire meg in this one frame.
11:30We're going to break it down into chunks.
11:33And so because we use TCP/IP, let's say,
11:35we're using a TCP packet, we're going to have sequence numbers,
11:39acknowledgment numbers.
11:40And if it's UDP, it's going to be fixed size packets that go.
11:44And if they make it, they make it.
11:46If they don't, they don't.
11:47But definitely take a look at what's actually
11:49going on inside of the supplemental files real quick
11:52on the side and start taking a look at how the layers line up
11:56between OSI and TCP/IP and what's happening in real time
12:02because as we start to put this together throughout the course,
12:05we'll see that as we get a packet, more and more of this
12:08starts to make sense.
12:09Now, in the next Nugget, we're going
12:11to start diving into the different parts of TCP/IP.
12:13Now, don't worry.
12:15We're not really getting too deep in the weeds just yet.
12:18We're doing more of an introduction
12:20into the course itself and what is
12:22to come and to be expected as we start digging through this.
12:25So let's get familiar with some of the terminology.
12:27Let's get familiar with some of the supplemental files
12:30that we have together because we're going to do this together
12:33from beginning to end, and I'll be there with you
12:35every step of the way.
12:36I hope this has been informative for you,
12:37and I'd like to thank you for viewing.
Different parts of TCP/IP
0:00[AUDIO LOGO]
0:05So we have our basic understanding of TCP/IP down.
0:08Let's move into different aspects of how it's used inside
0:11of the network packet.
0:12Now, for that, we're going to be putting the cart ahead
0:14of the horse, if you will, just a little bit,
0:16and we're going to be going into our VM here
0:18momentarily, and looking at how some of these packets
0:21are actually broken down and the type of information
0:24that we can get from it.
0:25We're still going through that familiarization
0:27phase of getting everything down as far as where we go,
0:31what we do.
0:32And as we move forward through these Nuggets and skills,
0:35we'll start getting more in-depth
0:36on how to analyze and retrieve everything.
0:39Now, as you can see here, we started a packet capture
0:42on Wireshark, and we're just doing some basic stuff.
0:44I'm going to crank up Firefox here for a second,
0:47get a little bit of more traffic going across the wire,
0:49so we can get more than just the Multicast DNS going on.
0:53And then give me just a second.
0:55We'll take a stop real quick, and we'll
0:57examine some of the packets that we have
0:59and what they actually look like in raw format as well.
1:02And just like that, we actually have some packets on here
1:04that are more in the variety of what you would commonly see
1:08on a network packet capture.
1:10And one we have highlighted right here is a TCP packet.
1:13Now, looking at it from start to finish,
1:16we're taking a look at the frame overall, which
1:18is the packet itself, and going down to Ethernet,
1:22seeing that it came from the actual NIC that was on here.
1:27So we're talking about the physical layer still.
1:30And then as we go into IP protocol version,
1:32that's how we were communicating.
1:34Now, this one was done over IPv4.
1:37And if we go down even deeper, we
1:39can see that this was a TCP protocol.
1:41And we can dig deeper into that as well
1:44and figure out what exactly it was that we were looking at.
1:47Now, I have zoomed in here the actual TCP protocol section
1:52of that one individual packet.
1:54And as you can see on the bottom-left side,
1:57we're looking at the actual destination port.
1:59So this was going to an HTTP system.
2:03So we're looking at, supposedly, a web server.
2:06And on the right side of it, let me move over a little bit.
2:09You can see my OBS also maybe.
2:11But you can see that highlighted is 0050,
2:14and that's the hex translated over from the actual normalized
2:19output.
2:20So this is the raw packet itself,
2:22and that section highlighted right there
2:25in that offset is the actual protocol and port
2:28number that's actually being used in this packet.
2:32Now, inside of the actual terminal
2:34itself, let me zoom in here for us real quick, what we're
2:37taking a look at is actual traffic
2:38as it's going through tcpdump.
2:41Now, we can export this to a PCAP file or something similar
2:44and import it into Wireshark, which we'll do later.
2:47But I'm going to do a stop here real quick, so we can actually
2:50take a look at some of the headers
2:52and get an idea of what's actually going on here.
2:54Now, this particular packet that I have highlighted here--
2:57makes sure it's in frame shot--
2:59is the actual headline of what's going on
3:02and not the actual packet itself.
3:03We can do more specific extracting
3:06of data packets using tcpdump later on,
3:09but the command that I use for this
3:11was simply sudo space tcpdump.
3:14And I'll have that below here so that way,
3:16we can keep track of what's going on.
3:18But being able to look at this header by itself
3:21if we were sending all just this overlay information
3:24to a text file, let's say, and we
3:27could see that the time, what protocol it was using.
3:29In this case, IP.
3:31Now, in this case, IP means IPv4 because it's by default.
3:35You'll see on the next line that it says IP6,
3:38and that's doing the whole IPv6 address.
3:41So you get the source, the protocol,
3:44and where it's going to, and the protocol as well, and along
3:49with some other information that's coming back
3:51in the packet itself, and this is
3:52where if we do the full-packet extraction,
3:55we could get more in-depth information from this.
3:58Now, I'm going to put up on the screen one of those lines
4:01here real quick, and we're going to do a play at home
4:04and challenge yourself for just a second.
4:06If you run this at home and you get
4:08this kind of output, what we're looking at on the screen
4:10right here is a quick overview of what
4:14you'll get in your output.
4:16And being able to look at this individually,
4:18we can see that, yeah, we have the timestamp
4:21and the actual IPv4 or IPv6 method that it was using,
4:26but we're also looking at the IP address.
4:28And you'll notice that it's followed by a .1.mdns.
4:32And that .1 is the actual port of UDP, in this case,
4:38and the .mdns is the actual protocol.
4:42So Multicast DNS.
4:44And then the Pac-Man sign is letting
4:48us know where it's coming from and going to.
4:50So the following IP address of 224.0.0.251 is the destination,
4:57and you'll notice it's followed by another .mdns,
5:00which is Multicast DNS.
5:02And for the purposes of this exercise, that's
5:04all we're really taking a look at right now,
5:06is just getting an idea of how to read this and get
5:11an understanding of it.
5:12So that way, when you run your examples at home and do this,
5:15you get an idea of--
5:17if something looks different, you
5:19know already where things are placed
5:22and know how to take a more detailed look at them.
5:25So I know we scratched the surface on where
5:27we get some of this information from, but in the next Nugget,
5:30we're actually going to start digging
5:31a little bit deeper into how to get better packets and better
5:34dumps from our command-line or terminal
5:37and also our Wireshark.
5:39Now, we're going to have a skill dedicated to Wireshark
5:42and going way more in detail.
5:43But since we've already touched on it
5:45and there are plenty of skills here
5:47on Wireshark in CBT Nuggets, we're
5:51jumping past the introductory level of installation
5:54and going straight to using its basic functions
5:57in that next Nugget.
5:58I hope this has been informative for you,
6:00and I'd like to thank you for viewing.
Were do we Get These Packets From?
0:00[AUDIO LOGO]
0:05Now, we've seen some examples of breaking a packet down
0:08and looking into it a bit.
0:09But as we hinted in the last Nugget,
0:11these have to come from somewhere, right?
0:14And in this Nugget, that's what we're doing here,
0:16is we're going to start diving into where
0:18we get this information from and, more specifically, what
0:21it is that we're kind of looking at,
0:23without going too far deep into the packet
0:25itself because we do have skills coming up later that
0:28will focus on those individual aspects of the packet overall.
0:32So we can start diving into whether it's
0:33TCP, UDP, IPv4, IPv6, what the payload is,
0:37and all this other great stuff.
0:39But for now, we just need to get a handle on how
0:41we extract the data itself.
0:43And primarily, inside of a network or system,
0:48there's two different methods that we use.
0:49And the first one that we're going to take a look at
0:52is tcpdump because that's one of the commands
0:54that we rely on heavily, not just in this course
0:57but if there were a certification for this course.
1:00Now, we're in our Kali VM.
1:01And we're taking a look at the terminal here.
1:03And I will put this command below.
1:05And we'll kind of walk through what's actually going on here.
1:07So sudo first and foremost-- so that way,
1:09we run it as an administrator-- and tcpdump.
1:13Now, there is an option to put a -i in here.
1:16And that's identifying the interface.
1:18So if we have a system with more than one interface,
1:20we would follow it up with, which interface is it?
1:23Now, those interface names come from your ifconfig.
1:26So if you're running, let's say, a VM
1:29or a physical box with multiple interfaces, you would use eth0,
1:34eth1.
1:35But the default, in this case, is
1:37eth0 on this system inside of tcpdump.
1:39So we're skipping the -i because we kind of know
1:42where all the traffic is coming from already.
1:44But our next command is -s lowercase with a zero on it.
1:49And what that does is it tells us kind of the size limitation.
1:52And the zero is identifying that this is an unlimited data size.
1:56Now, when we say data size, we're
1:58talking about, what's the data cap--
2:01what's the size cap on that actual packet that we're
2:03going to be capturing?
2:04So when we do our packet capture,
2:07if we have any packets that are, let's say, above 1,500,
2:11if we've identified that as our cap, anything 1,501 bytes
2:15and higher would not be captured.
2:17Now, this could be done for a variety of reasons.
2:20Let's say we have limited storage space.
2:22We have a need for only low-level,
2:25low-data rate stuff like broadcast packets,
2:29ICMP, et cetera, et cetera, stuff
2:32that normally doesn't have that big of a payload on it.
2:35But since we're doing just a short demonstration,
2:37we're going to leave this unlimited with -s0,
2:41lowercase s, because we want to pick up
2:43every packet that goes across.
2:45Now, the -w here is what we're going
2:47to be using to identify where this actually
2:50goes to for storage.
2:51And as you can see, we're putting it on our Desktop
2:54and calling it dumptest.pcap.
2:56Now, why pcap format?
2:58Well, there's a couple of different ways
2:59to skin the pcap cat.
3:01And we're going to show one for sure.
3:04And later on in this skill, we'll show another.
3:06First, we're going to use Wireshark to kind of go
3:09into it because pcap is a native thing inside of Wireshark.
3:13We'll also see here in a minute that we
3:15can kind of export our captures in pcap format from Wireshark
3:20itself.
3:21Now I'm going to go ahead and run this.
3:22And while it is running, after we type in our sudo password,
3:26I want to give a couple of tidbits
3:27to listen to as we open up our web browser
3:30and go to a random website to generate some traffic.
3:35One thing that we have to remember
3:37is that when we run things in GUI or terminal,
3:40we have to consider what the processing power is
3:43on that individual system.
3:44Now, this is a VM with limited resources.
3:47We're running 2 gigs of RAM.
3:48And we're also doing some other nefarious things on here
3:52through the different skills and courses that we've had
3:54together.
3:55So when we do a packet capture, it
3:57might be wise to run an actual command-line interface
4:01form of packet capture.
4:03If we go back over to it real quick,
4:05we'll see that it is capturing with a length of 262,144.
4:11And we can also see that it is listening on eth0 by default,
4:16like we stated.
4:16Now, we're not seeing anything in here,
4:18because it's all going to an actual file
4:21on the desktop, which I can find right here.
4:24And as we stop that, we can right-click on it
4:28and go into Properties and see that the file size is already
4:321.5 megs.
4:34Now, if we're using a GUI system or software to do this,
4:38like Wireshark, we have to keep in mind--
4:40and I'm going to pop out and see if I
4:43can zoom in here real quick.
4:46Right there, next to the icon for the network,
4:49is kind of where the processing for VMware shows--
4:53or for Kali shows inside the OS.
4:56And based on the limited resources, the more stuff
4:59you put in there running off a GUI, the more
5:01processing it adds to it because it has
5:03to render it in graphical form.
5:05So that's where the pros and cons are coming in at.
5:08If you're looking for something specific
5:09in a very short period, Wireshark
5:11might be the best way to go.
5:12If you're looking to do a capture of a broad scale
5:15and it's going to be capturing a lot, tcpdump or something
5:18else preferred by the user in CLI might be the better option.
5:23But overall, we can bring them into Wireshark.
5:25And that's what we're going to do here
5:27because now with that file on our desktop, we can open it up.
5:32And that's it right there in gedit.
5:36And I don't know why it went into gedit.
5:37That's OK.
5:38We're going to right-click and say, open up with Wireshark.
5:41It happens sometimes.
5:43And as we open it up in Wireshark,
5:45we can see that a lot of data has already been captured.
5:48And this is everything that we would normally
5:50get inside of Wireshark, especially in promiscuous mode.
5:53It just happened quicker for us inside
5:56of the tcpdump in our CLI.
5:59And we can see up at the top that our peaks are starting
6:02to come up for processing because we opened up
6:05a large file.
6:06And we are doing it with GUI.
6:08So if we take a look at it--
6:10I left this open for a reason.
6:12If we take a look at this, that's
6:15a lot of unintelligible text.
6:18Well, that's because it's doing it in hex.
6:20And if you wanted to be able to read it-- let me open one up
6:23for you right here and move it over for you--
6:26this is what it would actually look like,
6:28which we have the option to view this inside of our Wireshark
6:32down on the bottom right-hand side when
6:34we look at the data extraction.
6:38There we go.
6:39And right here, this is the actual packet itself.
6:42Now, you'll notice that there's a lot highlighted there.
6:44And that's the actual payload of what's going on.
6:47And again, this is all OK because we're going to take
6:49a step back and look at this from a bird's-eye view
6:53and start going back into our box examples again.
6:55Addendum-- I wanted to do something real quick
6:58and show you before we start getting into the weeds on this
7:01that we can actually go down to our bottom right
7:03on the actual Wireshark.
7:05Right-click.
7:06Sorry, my camera glitched there for a second.
7:08And we can actually show it as bits.
7:11And this gives us everything in the actual binary
7:14format of what's actually going on in that packet
7:18in the binary form.
7:19So we can actually see how it's broken down.
7:22And this lines up better.
7:23If you notice the zero, the eight--
7:25let me zoom in for you there right quick--
7:270, 8, 10, 18, 20.
7:29And those are our line numbers.
7:31Now, why does this matter?
7:32Well, as a sneak peek into something
7:34that we're going to do later in this course,
7:36we come back over here to our page two
7:38in our supplemental files.
7:39And we can see at the very beginning-- now,
7:41this is the IPv4 header and not the overall packet itself--
7:47that we have a 0000.
7:51We have 0008 and 0010.
7:55Those are the actual line numbers and help us line up
7:57with what's going on here.
7:59So if we're taking a look at it for funsies
8:01of what's going on here, this one right here--
8:04again, let me zoom in.
8:06Oh, wrong one.
8:070000 lines up with line zero in the actual PDF that we have.
8:148, 10, and then so on, so on, so on.
8:17So if we're looking at it from the packet overall
8:20and we want to compare it to what's actually going on inside
8:23of our supplemental files, we can start piecing together
8:26how this works together.
8:28Now, as an actual bonus to this--
8:31I know bonuses all day, right--
8:33that's a lot of information.
8:34And we know that the first byte right here, the first eight
8:38bits that we see right here, line up
8:40with zero through seven.
8:42And yep, I can highlight them right there-- zero
8:44through seven.
8:45So that would be byte offset zero.
8:48And we can look.
8:49What's the IP header length?
8:50Well, if we were on the right one
8:53and this was an actual IPv4 header packet, then
8:56that would tell us that it's on the actual length of zero.
9:00But this allows us to be able to take information
9:03that we see in binary form and bring it over to something
9:06that's more intelligible to us.
9:07The reason that we do the stuff like this--
9:09and we'll see all throughout this course--
9:11is that we could use programs like Scapy--
9:13and it's coming-- that we can modify and create
9:16crafted packets to kind of look like they're
9:19supposed to be real but put stuff in there that
9:21doesn't make sense.
9:22So we would expect an IP header in the byte offset of our form
9:27or packet diagram right here to be either a four or a six,
9:31right?
9:32Well, what if we had IP version 7 coming across?
9:35Well, there's no RFC, or Request For Comment,
9:37that's come out for it.
9:38So we need to keep an eye out for stuff like this.
9:40And that's why we're diving into it throughout this course,
9:43to get an understanding of how these packets are put together.
9:46And if you're lost in the sauce, like I am,
9:50when it comes to binary and hex and all this other stuff,
9:53the last page of our supplemental files--
9:55let's see if--
9:57yeah, I got it.
9:59Right here, this is an actual conversion chart,
10:01where it goes from decimal, binary, hexadecimal.
10:04And we can go in here and see that, for example,
10:07on the top left, all eight zeros equal a hex of zero.
10:12Well, you can go through here and do this conversion.
10:15And it would make sense to you if you
10:18had to convert some of these, let's say,
10:19for an exam or something like that.
10:21Who knows?
10:22OK, so we went through and figured
10:23out how to copy traffic as far as in a live environment
10:27through the CLI and the GUI.
10:29We're talking like tcpdump and Wireshark.
10:32But what if we wanted to replay that traffic?
10:35I'm a step ahead of you.
10:36And that's what's coming up in the next Nugget.
10:38I hope this has been informative for you,
10:40and I'd like to thank you for viewing.
Replay the Traffic
0:00[AUDIO LOGO]
0:06What happens if we've recorded the traffic
0:08but need to replay it?
0:10So we got our pcap right here.
0:11And we've already copied everything into that pcap
0:15by recording the traffic and whatnot.
0:16But what if we wanted to replay it?
0:18Now, I know what you're thinking.
0:20What?
0:20Why replay it?
0:21Well, let's say we copy the pcap from our regular live network
0:25and go to a honey net or a honey pot
0:28and we want to replay it to see what exactly happened?
0:31We could be trying to test out if somebody was doing an IPS
0:34or IDS evasion tactic or if there
0:36was some nefarious traffic that we missed.
0:39Well, that's where we use tcpreplay.
0:42And I'm going to fire up the Wireshark here.
0:46I'm going to close out this one.
0:48And we're going to open up a fresh copy of Wireshark.
0:52Now, we're going to use this on our loopback.
0:55And the reason we're doing that is
0:56because everything on our eth0, if we do it
0:59in promiscuous mode on Wireshark,
1:01it's going to come back and record everything, let's say,
1:03like if we were go to the web or something like that.
1:06So we can use a command called tcpreplay in our command line.
1:10And we'll type in sudo tcpreplay.
1:15And then the I is the interface that we're going to put it on.
1:19Now, again, I'm going to do a real quick ifconfig
1:23to make sure that we have our local loopback.
1:25And that is right there-- the lo.
1:27So we're going to go sudo tcpreplay -i lo.
1:33And then we're going to say--
1:38just type in the actual location of the pcap file,
1:41which is /home/kali--
1:45make sure we recognize our lower and uppercase here because it
1:48is case sensitive inside of Unix-based systems--
1:51on our Desktop and dumptest.pcap.
1:58Now, I'm going to go ahead and go into our Wireshark here.
2:01Make sure that we have local loopback selected.
2:04And start our capture on there.
2:06And then go ahead and do this right here.
2:09Complete the command and start our replay.
2:11Now, if we open up our Wireshark,
2:13we can see that we're replaying all that traffic from the PCAP
2:16in our local loopback.
2:18This allows us a method to be able to capture
2:20traffic and replay it for analysis later
2:23on in a more detailed method.
2:25And you can also see that it's doing it in the same time frame
2:28that it captured it in to begin with.
2:30It didn't just do a sporadic dump and show everything
2:34all at once.
2:35It's doing it in a timed fashion that it caught it in.
2:37Now, I'm going to go ahead and do a stop because I
2:40don't need that entire thing.
2:41This just gives us a tool to where
2:43we can understand that we do a capture either through tcpdump
2:48or Wireshark.
2:49And we can use the CLI and tcpreplay
2:52to play it back to a specified interface
2:54and bring it back into something else for collection
2:58to make sure that, let's say, the original capture matched
3:02what the replay was giving us, in case
3:04there was something that slipped in that we didn't know about.
3:06Or what if something's missing and we need more info on it?
3:09Now, we're not going full on into it in this skill.
3:12That's what we have plenty of other skills
3:14throughout this course for.
3:15But this is, again, more of an introductory skill
3:18to the entire course overall in the basic concepts of this
3:21and TCP/IP.
3:23But in the next Nugget, we're going to go a little bit deeper
3:26into that hex and binary that we were talking about while ago
3:29and cover some methods that make it a little bit easier for us
3:32to be able to understand what's going on without having
3:34to dig too deep into it.
3:36I hope this has been informative for you,
3:37and I'd like to thank you for viewing.
Learning Binary and Hex
0:00[AUDIO LOGO]
0:05Now, don't worry because this isn't something
0:07we have to memorize, but we do need to get familiar with it
0:10and learn the basics.
0:11And of course, I'm talking about hex binary decimal and all
0:15that great stuff.
0:16And in this Nugget, we're actually
0:17just going to do a quick review over how to--
0:20basic identification and the simple math that
0:23actually goes behind it.
0:25So I'm going to make this as painless as possible
0:28because this is not something that we have to memorize.
0:30We just have to be aware of what this is, how it's done,
0:34and if we need to use it later on, let's say,
0:37spur of the moment, and we have just an idea
0:39of what it is that we need to do and how we do it.
0:42Now, of course, I do want to point out again,
0:45the last page has a master conversion chart
0:48in our supplemental files of almost every possibility
0:53that we will run into when we do network analysis or network
0:56monitoring.
0:57So let's say, just a weird one, we have a decimal of 255,
1:02and the binary for it is all 1's, and the hexadecimal for it
1:07is ff.
1:08So don't be afraid to use this chart and any other source
1:13out there to be able to do this because it's not
1:16like the real world is going to be a testing environment.
1:19You can have stuff like this on you if you need it.
1:22Now, that being said, what we're taking a look at here
1:24is a graph that's going to fill in
1:26as we go through the different portions of it,
1:28and on the first line is how we actually count binary.
1:32So we see that we start from the left and work our way
1:35all the way over to the right, starting at 128
1:38and going back down to 1.
1:39Now, for those that were in the networking before this,
1:41this may look a little bit familiar
1:43because this is actually how we do
1:44subnetting to a certain degree.
1:46So let's go ahead and reveal our next line, which is 00001001.
1:53Now, that's our traditional binary-type format,
1:56where we have nothing but 0's and 1's.
1:58And revealing it to the side, we have that this
2:02is a decimal equaling 9.
2:04Now, where do we get that from?
2:06Well, if we notice that the first one that we
2:08run across going from left to right is under the eight column
2:12and the next one is under the one column,
2:14we're simply just going to add those two together and get 9,
2:17and that gives us our decimal formatting.
2:20Well, on the next line, let's go ahead and reveal it.
2:23We have 00000111.
2:27Now, I'll give you just a second to figure out
2:29what this equals up because again, we're just adding
2:32the 4, the 2, and the 1 column.
2:34And if you guessed 7 or got 7, you are correct.
2:37This is a decimal value of 7, so we have converted from binary
2:41to decimal.
2:42And behind door number 3 is our last one,
2:45where we're going to go 00010011.
2:49And by their powers combined, it is equal to 19
2:53because we're adding 16, 2, and 1.
2:56For an added little bonus to this,
2:58I'm going to add another column in here,
3:00and you'll notice on the top-right, I just revealed.
3:02It it's hex, short for hexadecimal.
3:05Now, this is going to get a little wonky really quick
3:09because in our first column, we said that we
3:10had a decimal value of 9.
3:12Well, that equals 9.
3:15You may be thinking, that's not too bad.
3:17And in the next column or the one right below it,
3:20we have a decimal of 7, and that equals 7.
3:23Well, in our third example, and I'm using this one because it's
3:26pretty easy to figure out, we have a decimal value of 19,
3:30but our hex value is--
3:32I'll give you 1 second--
3:3413.
3:34Now, you may be thinking, what in the world is going on here?
3:37And that's what I first thought when I ran across this too.
3:40But now, I'm revealing right below it,
3:42and you can see that 19 divided by 16
3:45equals 1 with a remainder of 3.
3:47And if you can see, that does calculate in there.
3:50Now, for those playing at home, if you did a decimal value
3:54of 18, which would be binary 00010010,
4:01your decimal value would be 18, and your hexadecimal for that
4:05would be 12, not just because it's one lower 19.
4:07I get it.
4:08But it's because 18 divided by 16
4:12equals 1 with a remainder of 2.
4:14Now, there are many different calculations
4:17that we could do with this because of the fact
4:19that we have to divide by 16, and that's hexadecimal.
4:23But we're making this easier on ourselves
4:25and just referring to the chart that we
4:27have to be able to do our conversions.
4:29Now, if you're like me and some of this
4:34overwhelms you sometimes, that's OK, too,
4:36because what we're doing now is going
4:37to take a look at an actual website
4:39that we could use to help us.
4:41And I go to this site all the time
4:44to be able to do bigger conversions on if-- basically,
4:47if it's outside of what I can do in my own head,
4:51I go here because I don't want to strain too hard over it,
4:54and I just go do a quick decimal to hexadecimal conversion,
4:58and this also does binary.
4:59And if you scroll down after we do one,
5:02it'll actually show you the steps of how the math actually
5:04got involved in it.
5:05I will put this link below.
5:07So what we're doing now is we're going to do a simple decimal,
5:10which would be, let's say, 126, and we're going to make sure
5:14it's set to hexadecimal and do a convert,
5:16and we see it converted to 7 echo, which is 007 echo.
5:23The binary for that is 11111107.
5:27Seven digits.
5:28And if we scroll down, we can see right here,
5:31this is where the math is actually
5:33done to give us where we got 7 echo and how it lined up
5:36and everything like that.
5:37So I know that there's a lot of math that
5:40goes into the actual hexadecimal conversion of this,
5:42but thankfully, for the purposes of this course
5:45and if there was an exam associated with this,
5:47we don't have to do the math in our heads
5:49while we're on the test.
5:51What this is, is just giving us familiarity and figuring out
5:54what's actually going on behind the scenes
5:56because when we break those packets down,
5:58like we've seen before, there is hexadecimal,
6:00and we may need to convert it for whatever reason,
6:03from hex to decimal and/or binary.
6:06Now, like I said, that was just a quick familiarization
6:09because we didn't want to go too deep into the math.
6:11It's not like we're trying to do calculus here or anything
6:14like that.
6:15But in the next skill, we're going
6:16to be diving more deeply into Wireshark.
6:19So that one, we will get way all the way up to the waist
6:22in the swamp on that one.
6:23But that's OK because the more we know about Wireshark,
6:26the more we're able to analyze the traffic that's
6:28coming across the wire and can make a better determination
6:31of that traffic for those folks up
6:33in the C-suite with the security policy and whatnot.
6:36So I hope this has been informative for you,
6:38and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year