Question: 4. Using http://www.garykessler.net/library/file_sigs.html as a guide, determine the first 4 bytes of the file signature of the downloaded file based on the file type and


4. Using http://www.garykessler.net/library/file_sigs.html as a guide, determine the first 4 bytes of the file signature of the downloaded file based on the file type and extension. What are the first 4 bytes of the hexadecimal signature of the file that was downloaded? 109.160.0.1 189-184.9.7 187.149.4.1 180.180.0.1 109.14.0.1 FTP 120 Imperial 125 fats comaction closely spes; transfer starting Figure 7: File Type Using Hexadecimal Value Source: Wireshark v2.4.3 . Using the Gary Kessler library for file signatures I was able to conclude that the hexadecimal value for a Rich Text Format (RTF) file is "78 5C 72 74 66" 5. Find and extract the file from the pcap file. Clear all Wireshark filters and search the entire pcap file in Wireshark for the first 4 hexadecimal bytes of the downloaded file based on the file signature
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
