A complaint came in that a certain organization is hosting an illegal FTP site to download copyrighted
Fantastic news! We've Found the answer you've been seeking!
Question:
A complaint came in that a certain organization is hosting an illegal FTP site to download copyrighted software. The security team has provided a pcap file capturing all FTP traffic on the network. They've asked you to identify where the FTP site is being hosted.
- Please provide detailed steps using wireshark to solve and recognize the PCAP file
- Below is a screenshot of the wireshark application
Transcribed Image Text:
WGU-Win10-GNS3 Ticket2.pcap.pcapng File Edit View Go Capture Analyze Statistics Telephony Wireless Tools Help Press esc to exit full screen O Q+E Q QQ T Apply a display filter ... Time No. 1 0.000000 2 0.000388 3 38.709094 4 38.709663 5 38.712669 6 38.715618 7 38.718031 LOTTEE 8 43.798455 * 9 43.798938 10 48.076252 ******** 11 48.076682 12 48.076770 13 48.080162 14 50.727052 07 Source Ticket2.pcap.pcapng 0c:2c:41:b7:00:00 0c:c1:25:31:00:02 0c:c1:25:31:00:02 0c:2c:41:b7:00:00 10.10.60.1 10.10.20.2 10.10.60.1 AUTOTE 10.10.20.2 AUTEUTENTE 10.10.60.1 aufer:26 0c:fc:ae:26:00:00 0c:c1:25:31:00:02 www 10.10.60.1 10.10.20.2 10.10.20.2 10.10.60.1 10.10.60.1 0000 0c c1 25 31 00 02 0c 2c 0010 08 00 06 04 00 01 0c 2c 0020 0 1 25 31 00 02 0 Destination 10.10.20.2 10.10.60.1 10.10.20.2 10.10.60.1 10.10.20.2 0c:c1:25:31:00:02 0c:fc:ae:26:00:00 CONS www 10.10.20.2 **** 10.10.60.1 10.10.60.1 10.10.20.2 10.10.20.2 41 b7 00 00 08 06 00 01 41 b7 00 00 ea ea 14 03 14 fe > Frame 1: 42 bytes on wire (336 bits), 42 bytes captured (336 bits) on interface -, id e > Ethernet II, Src: 0c:2c:41:b7:00:00 (0c:2c:41:b7:00:00), Dst: 0c:c1:25:31:00:02 (0c:c1:25:31:00:02) > Address Resolution Protocol (request) %1 Protocol ARP ARP TCP TCP TCP FTP TCP 200 ARP -%1 .. ARP M FTP TCP FTP TCP FTP Length Info 42 Who has 10.10.20.254? Tell 10.10.20.3 42 10.10.20.254 is at 0c:c1:25:31:00:02 A A 66 54414 21 [ACK] Seq=1 Ack=36 Win=64256 Len=0 TSval=1528451789 TSecr-2636475934 60 Who has 10.10.20.254? Tell 10.10.20.2 42 10.10.20.254 is at 0c:c1:25:31:00:02 82 Request: USER anonymous 66 21 54414 [ACK] Seq=36 Ack-17 Win-65280 Len=0 TSval-2636485295 TSecr=1528461146 100 Response: 331 Please specify the password. 66 54414 21 [ACK] Seq-17 Ack-70 Win-64256 Len=0 TSval-1528461151 TSecr=2636485295 73 Request: PASS 74 54414 21 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1 TSval=1528451779 TSecr=0 WS=128 74 21 54414 [SYN, ACK] Seq=0 Ack-1 Win=65160 Len=0 MSS=1460 SACK_PERM=1 TSval-2636475928 TSecr=1... 66 54414 21 [ACK] Seq=1 Ack=1 Win=64256 Len=0 TSval-1528451783 TSecr=2636475928 101 Response: 220 Welcome to warez FTP service. Send Ctrl+Alt+Delete Packets: 44149 - Displayed: 44149 (100.0%) 0 X + Profile: Default Reboot WGU-Win10-GNS3 Ticket2.pcap.pcapng File Edit View Go Capture Analyze Statistics Telephony Wireless Tools Help Press esc to exit full screen O Q+E Q QQ T Apply a display filter ... Time No. 1 0.000000 2 0.000388 3 38.709094 4 38.709663 5 38.712669 6 38.715618 7 38.718031 LOTTEE 8 43.798455 * 9 43.798938 10 48.076252 ******** 11 48.076682 12 48.076770 13 48.080162 14 50.727052 07 Source Ticket2.pcap.pcapng 0c:2c:41:b7:00:00 0c:c1:25:31:00:02 0c:c1:25:31:00:02 0c:2c:41:b7:00:00 10.10.60.1 10.10.20.2 10.10.60.1 AUTOTE 10.10.20.2 AUTEUTENTE 10.10.60.1 aufer:26 0c:fc:ae:26:00:00 0c:c1:25:31:00:02 www 10.10.60.1 10.10.20.2 10.10.20.2 10.10.60.1 10.10.60.1 0000 0c c1 25 31 00 02 0c 2c 0010 08 00 06 04 00 01 0c 2c 0020 0 1 25 31 00 02 0 Destination 10.10.20.2 10.10.60.1 10.10.20.2 10.10.60.1 10.10.20.2 0c:c1:25:31:00:02 0c:fc:ae:26:00:00 CONS www 10.10.20.2 **** 10.10.60.1 10.10.60.1 10.10.20.2 10.10.20.2 41 b7 00 00 08 06 00 01 41 b7 00 00 ea ea 14 03 14 fe > Frame 1: 42 bytes on wire (336 bits), 42 bytes captured (336 bits) on interface -, id e > Ethernet II, Src: 0c:2c:41:b7:00:00 (0c:2c:41:b7:00:00), Dst: 0c:c1:25:31:00:02 (0c:c1:25:31:00:02) > Address Resolution Protocol (request) %1 Protocol ARP ARP TCP TCP TCP FTP TCP 200 ARP -%1 .. ARP M FTP TCP FTP TCP FTP Length Info 42 Who has 10.10.20.254? Tell 10.10.20.3 42 10.10.20.254 is at 0c:c1:25:31:00:02 A A 66 54414 21 [ACK] Seq=1 Ack=36 Win=64256 Len=0 TSval=1528451789 TSecr-2636475934 60 Who has 10.10.20.254? Tell 10.10.20.2 42 10.10.20.254 is at 0c:c1:25:31:00:02 82 Request: USER anonymous 66 21 54414 [ACK] Seq=36 Ack-17 Win-65280 Len=0 TSval-2636485295 TSecr=1528461146 100 Response: 331 Please specify the password. 66 54414 21 [ACK] Seq-17 Ack-70 Win-64256 Len=0 TSval-1528461151 TSecr=2636485295 73 Request: PASS 74 54414 21 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1 TSval=1528451779 TSecr=0 WS=128 74 21 54414 [SYN, ACK] Seq=0 Ack-1 Win=65160 Len=0 MSS=1460 SACK_PERM=1 TSval-2636475928 TSecr=1... 66 54414 21 [ACK] Seq=1 Ack=1 Win=64256 Len=0 TSval-1528451783 TSecr=2636475928 101 Response: 220 Welcome to warez FTP service. Send Ctrl+Alt+Delete Packets: 44149 - Displayed: 44149 (100.0%) 0 X + Profile: Default Reboot
Expert Answer:
Answer rating: 100% (QA)
To identify the FTP servers host location within a network using Wireshark and the given PCAP file you can follow these steps 1 Open the PCAP file in ... View the full answer
Related Book For
Posted Date:
Students also viewed these algorithms questions
-
Bribie Thriller Company has debt outstanding with a book value of $30 million. The debt is trading in the market at 90 per cent of book value. The yield to maturity at current market prices is 10 per...
-
I have this data frame with the years and values, can you make a model to predict the value of meats,fish,fruits and vegetables and grains? based on the current values of the table and historical...
-
How is the direction of an electric field indicated with electric field lines?
-
The Broughton Cap Company requires that prenumbered receiving reports be completed when purchased inventory items arrive in the receiving department. At the time of receipt, the receiving clerk...
-
A tornado has the following velocity components in polar coordinates: \[ V_{r}=-\frac{C_{1}}{r} \quad \text { and } \quad V_{\theta}=-\frac{C_{2}}{r} \] Note that the air is spiraling inward. Find an...
-
For his portfolio, Jack Cashman randomly selected securities from all those listed on the New York Stock Exchange. He began with one security and added securities one by one until a total of 20...
-
Discuss the role of lean manufacturing principles in enhancing quality and efficiency, analyzing the reduction of waste, implementation of visual management systems, and the use of value stream...
-
Sunnyville Bank wants to identify customers who may be interested in its new mobile banking app. The worksheet called Mobile_Banking_Data contains 500 customer records collected from a previous...
-
Explain how Information Technology (IT) promotes people who are affected by policies involved in the policy-making process
-
7. Let f(x) = 1 (a) (5 points) Calculate f'(1) by using the limit definition of the derivative. If you get the wrong answer using the limit, then you can simply state the derivative using the...
-
A car manufacturer has the following total cost function: TC=200+50 Q + 2Q a) Is this a short run or long run cost function? Why? b) Compute the average total cost of producing cars, AC, and show...
-
Think about a group you have worked in either at school, work, or in the community. Recall any small group conflicts related to group task roles. (Please do not use real names if describing a...
-
Brady Telecom sells commercial computer systems with a fair value of $160,000 to customers for $180,000. The sale price includes an installation fee valued at $25,000. Installation is considered a...
-
A project's critical path has seven tasks (A through G) with expected durations and standard deviations as given below. a) What is the critical path's expected length? b) What is the standard...
-
Identification and discussion of relevant legal issues: Examination & analysis of information: Jerene, Joey and Xin are international students studying for a Hospitality and Tourism degree in...
-
This problem continues the Draper Consulting, Inc., situation from Problem 12-45 of Chapter 12. In October, Draper has the following transactions related to its common shares: Oct 1 Draper...
-
You are 30 years old and obtained your MBA from a top business school two years ago. You are being promoted to be CEO of a multibillion-dollar firm that is publicly listed in your country. There is...
-
Hypothetically, your MNE is the largest foreign investor in (1) Vietnam, where religious leaders are being prosecuted; (2) Estonia, where ethnic Russian citizens are being discriminated against by...
-
From institution-based and resource-based views, identify the liability of foreignness confronting MNEs from emerging economies interested in expanding overseas. How can such firms overcome them?
-
What is arms-length pricing?
-
We discussed risk aversion as being descriptive of investor behavior. Can Do you think of any real-world behavior that you might consider to be evidence of the existence of risk preferrers?
-
In Section 6.2.3, we made the comment "Perception is reality." How does this play in the valuation of a tangible versus intangible asset? 6.2.3 Politics to explore Our roadmap for this chapter would...
Study smarter with the SolutionInn App