Question: Challenge Lab 5-1: Capturing and Identifying the Three-Way Handshake Time Required: 30 minutes Objective: Determine which packets create the three-way handshake used in establishing


Challenge Lab 5-1: Capturing and Identifying the Three-Way Handshake Time Required: 30 minutes Objective: Determine which packets create the three-way handshake used in establishing a communication session. Required Tools and Equipment: Net-XX with Wireshark installed Description: Using Wireshark and a suitable capture filter, capture the packets involved in an HTTP session that you start by opening a Web page. Find the three packets that constitute the three-way handshake. Perform the following tasks and answer the following questions: What capture filter did you use to limit Wireshark to capturing only packets related to HTTP? Find the three-way handshake that immediately precedes the first HTTP packet. Which Transport-layer protocol was used to create the connection? Client State CLOSED SYN-SENT ESTABLISHED Client Wait For Server Active Open: Create TCB, Send SYN SEO-AND Wait for ACK TO SYN Recevie SYN+ACK, Wireshark Info Wireshark offers relative sequence numbers (turned on by default) SEO-ACK ACK-STO TCP.Flags.SYN-1, SEQ-OLEN-0 SVN TCP.Flags.SYN-1, TCP.Flags ACK-1 SEQ-0,ACK-1,LEN-O SYN+ACK Send ACKPACK-1 SEQ=1 ACK=1,LEN-O ACK Passive Open: Create TCB Server Wait For Client Receive SYN, Send SYN+ACK SEO-RNDX ACK-SEO+1 Wait for ACK TO SYN Receive ACK TCP 3 WAY HANDSHAKE Filter tcp.flags.syn==1|| (tcp.flags.ack==1&& tcp.seq==1&& tcp.ack==1&& !tcp.nxtseq>0) Server State CLOSED LISTEN SYN-RECEIVED ESTABLISHED
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
