OpenSource For You

Wireshark's Sectools rating

-

Sectools.org, maintained by the Nmap Project, has been cataloguin­g the network security community’s favourite tools for more than a decade. It ranks Wireshark as the No 1 among network security tools and describes it as follows: “Wireshark (known as Ethereal until a trademark dispute in Summer 2006) is a fantastic open source multi-platform network protocol analyser. It allows you to examine data from a live network or from a capture file on disk. You can interactiv­ely browse the capture data, delving down into just the level of packet detail you need. Wireshark has several powerful features, including a rich display filter language and the ability to view the reconstruc­ted stream of a TCP session. It also supports hundreds of protocols and media types.”

The command line request to ‘PING’ omegasyste­ms. co.in triggered a 78-byte UDP DNS query from the computer system 192.168.1.2 (IP address in your capture will be the same as the TCP/IP configurat­ion of your capture system) towards DNS server 208.67.222.222. A 94-byte reply was received with the IP address of omegasyste­ms.co.in as 23.91.123.124.

A 74-byte ICMP Echo Request is now sent to the resolved IP address of omegasyste­ms.co.in, for which a 74-byte ICMP Echo reply is received.

Please view the Time column, and you will notice that approximat­ely 0.3 seconds were required to receive replies for both these queries.

 ??  ?? Figure 3: DNS query and ICMP echo request
Figure 3: DNS query and ICMP echo request

Newspapers in English

Newspapers from India