CSIS 100
Page 1 of 5
L TAB: WIRESHARK PACKET CAPTURE ASSIGNMENT EMPLATE
Screenshot #1:
Question #1 How many seconds did your
capture run?
34.686235
Question 2: How many packets did you
capture?
I captured 12702 packets.
CSIS 100
Page 2 of 5
Screenshot #2:
Question 3: What colors are present in your
output?
There wes 6 colors (light purple, navy blue,
light blue, red, light green, gray)
CSIS 100
Page 3 of 5
Question 4: Are there any protocols that
appear with more than one color? Why or
why not?
Yes, the TCP appeared to be in navy blue
and light purple color. Because theres a
bad TCP when its highlighted in navy blue
CSIS 100
Page 4 of 5
Screenshot #3:
Question 5: How many rows are appearing
in your WireShark capture with the filter in
place? (Be careful with this...The “No.”
column represents the packet number – not
the number of rows currently visible.)
There only appears to be 2 rows with the
HTTP filter.
Question 6: What other protocols do you see
in the “Protocol” column?
Theres only HTTP protocol.
CSIS 100
Page 5 of 5
Screenshot #4:
Question 7: What is the host listed directly
below the GET / HTTP/1.1 command in your
TCP Stream output?
The host is www.bbc.com
Question 8: How many bytes is the entire
conversation?
Theres was 1930 bytes for the entire
conversation.
CSIS 100
Page 6 of 5
Screenshot #5:
Question 9: Compare the IPv4 address listed
in your ipconfig output to the IP address that
is listed under the Source column in your
Wireshark capture for the first “GET /
HTTP/1.1” row. Are these IP addresses the
same? Why or why not?
Yes, the IPv4 address is the same with the
IP address in the “GET / HTTP/1.1” row.
Because I was connected to the same
router.
Question 10: Click on the row of the next
packet in this conversation. Does your IP
address appear in the Source or Destination
column? Why?
Yes, my IP address from the first row of
the Source column appear to be the same
in the second row of the Destination
column. Because I searched up for
www.bbc.com on the same router.