Objectives
In this lab, you will use the Linux utility tcpdump to capture and save network traffic. You will then use Wireshark to investigate the traffic capture.
- Prepare the host to capture network traffic.
- Capture and save network traffic.
- View and Analyze the Packet capture.
Background / Scenario
Wireshark is a network packet capture utility that can be used by network administrators to troubleshoot network problems. It can also be used to eavesdrop on network communications to passively collect information about users and services. Wireshark is considered a passive tool because it does not create traffic on the network.
Required Resources
- Customized Kali VM
- Internet access
Instructions
Part 1: Prepare the Host to Capture Network Traffic.
Step 1: Start the virtual machine and log in.
- Start the Kali workstation virtual machine. Use the following user credentials:
- Start a terminal session.
Username: kali Password: kali
Step 2: Verify the environment.
- Verify the user directory that will be used to store the captured traffic. To display the current directory, use the pwd command. This will display the full path to the current working directory.
┌──(kali㉿Kali)-[~]
└─$ pwd- Determine the IP address of the Kali Ethernet interface using the ifconfig command. The ethernet interface is usually named eth0.
┌──(kali㉿Kali)-[~] └─$ ifconfig
- Determine the default gateway assigned to the Kali host using the ip route command.
┌──(kali㉿Kali)-[~] └─$ ip route
- Determine the address of the configured default DNS server by displaying the contents of the /etc/resolv.conf file. You can view the file using the cat command.
┌──(kali㉿Kali)-[~] └─$ cat /etc/resolv.conf
Part 2: Capture and Save Network Traffic.
In this part of the lab, you will use tcpdump from the CLI to capture traffic. You will use command options to save the traffic to a packet capture (pcap) file. These records can then be analyzed using different applications that read pcap files, including Wireshark.
Step 1: Open a terminal and start tcpdump.
- Open a terminal application and enter the command ifconfig.
- In the ifconfig output, find the interface name that corresponds to the Ethernet adapter (usually eth0). Right click the interface name and select Copy Selection.
- Enter the sudo tcpdump command as shown. Use the interface name that you copied in the previous step, as in the example below. This command requires root user access, so enter kali as the password if prompted.
┌──(kali㉿Kali)-[~] └─$ ifconfig
┌──(kali㉿Kali)-[~] └─$ sudo tcpdump -i eth0 -s 0 -w packetdump.pcap
The -i command option allows you to specify the interface. If not specified, tcpdump will capture all traffic on all interfaces.
The -s command option specifies the length of the snapshot for each packet. Setting this option to 0 sets it to the default of 262144.
The -w command option is used to write the result of the tcpdump command to a file. Adding the extension .pcap ensures that operating systems and applications will be able to read the file. All recorded traffic will be printed to the file packetdump.pcap in the home directory of the user.
Step 2: Generate network traffic using a web browser.
- To capture an HTTP request and reply, open a web browser in Kali desktop. Navigate to Google.com. Do not login or search.
- Open a second tab in the browser, enter netacad.com on the launch bar. When the page appears, click the user icon at the top right of the page. Log in with your login information.
- Return to the terminal window that is running the tcpdump utility and enter CTRL-C to complete the packet capture.
- The tcpdump utility saved the output to a file named packetdump.pcap. This file should be saved in the default home directory. Verify that the file exists in the directory using the ls command.
┌──(kali㉿Kali)-[~] └─$ ls packetdump.pcap packetdump.pcap
Part 3: View and Analyze the Packet Capture.
In this part of the lab, you will use Wireshark to analyze the packet capture file that you created in previous part of this lab.
Step 1: Open the Wireshark application to view the packet capture.
- Use Wireshark to view the captured packets. Launch the graphical Wireshark application by typing wireshark at the terminal prompt.
- Use the File -> Open menu option and browse to the pcap file. Click Open. A screen should open displaying the contents of the packetdump.pcap file.
┌──(kali㉿Kali)-[~] └─$ wireshark
The Wireshark application should open in a different window. Expand the Wireshark window to full screen.
Step 2: Analyze DNS traffic.
When you type a website URL into your browser, your PC performs a DNS query to the DNS server’s IP address. Observing DNS queries and responses provides the names (URLs) and IP addresses of sites a user visits. Knowing websites that are commonly visited by users can be valuable when formulating social engineering attacks.
- Filter the captured traffic to only display DNS queries and responses. Enter dns in the Filter Field on the Wireshark main screen. You will notice that in addition to the Netacad website that you requested, other DNS lookups are shown. These correspond to links contained within the Netacad and Google homepages.
- Click the magnifying glass search icon or choose Find Packet from the Edit menu. Search for the netacad.com hostname. Select String in the Display filter dropdown box and enter netacad in the search box. Click Find.
- Select the first Standard query for the netacad.com website. Expand the query details pane below the packet list to view the contents of the query packet.
- Expand the Ethernet II information to display the Layer 2 header data contained in the packet. The source MAC address is the MAC of the sending device interface, in this case the Kali VM, and the destination MAC address is the MAC of the default gateway because the DNS server is not on the same Layer 2 network.
- Expand the Domain Name System (query) section to see the details of what is being sent to the DNS server. It also indicates the line that contains the reply packet that was received in response to the query. Double-click the link to the response. The details of the Standard query response packet are shown.
- Close Wireshark to return to the CLI prompt.
Step 3: Analyze an HTTP Session
In this step, you will capture and analyze a web request and response. You will use Wireshark to capture the traffic and to analyze the messages exchanged between the web server and the client. The website server is a VM server running in a Docker container on the Kali Linux VM.
- Use ifconfig to determine which interface on the Kali Linux VM is configured in the 10.6.6.0/24 network.
┌──(kali㉿Kali)-[~] └─$ ifconfig
- Open Wireshark by typing wireshark at the command prompt. Wireshark will open in a new window, expand the window to full screen. At the center of the main Wireshark screen there will be a list of interface names to choose to capture traffic with. Double-click the interface is connected to the 10.6.6.0/24 network. This will start packet capture.
- Open a browser window and navigate to the IP address 10.6.6.13. A login screen for the DVWA web server appears. Enter admin as the username and password as the password.
- When the main DVWA page appears, click the Instructions button at the top of the menu on the left side of the screen. When the instructions page appears close the browser window.
- Return to the Wireshark window. Stop the capture using the red square icon on the menu bar. The DVWA web server is using HTTP, not HTTPs. Use the search icon to find the string POST in the captured packets. POST messages transfer form data from the client to the server, in this case the login information.
- Double-click the first POST packet to view the packet details in a separate window. Expand the section titled HTML Form URL Encoded:
Username: admin Password: password
- Cookies are used for various purposes. Most frequently, they are used to save information about a user’s session. Cookies can be hijacked and used in session hijacking attacks. The initial cookie for a session is sent from the web server to the client with the Set-Cookie value in a HTTP response. Use Ctrl-Home to return to the first line in the packet capture. Use the search icon to find the string 302 Found in the packet pane. Double-click the first packet that was found and expand the Hypertext Transport Protocol section.
- Examine the next GET packet being sent from the Kali client browser after receiving the cookie information. Expand the Hypertext Transfer Protocol section. Look for the Cookie values being sent in the packet.
- Close Wireshark. You will have the option to save the .pcap file containing the capture or to quit without saving. The .pcap file will be saved in the current working directory unless otherwise specified.