Is this an attack? Wireshark Packet analysis // SYN Attack

แชร์
ฝัง

ความคิดเห็น • 184

  • @SpragginsDesigns
    @SpragginsDesigns 3 ปีที่แล้ว +61

    Thank you for everything, David. After two years in college I was just hired last week as a remote Web and Mobile App Designer and Developer. Because I am also OSCP certified, it drastically raised my salary and the fun level of my position. And a lot of your courses are to thank for this; college is just for the paper or "degrees"."

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว +7

      That is awesome! Congratulations!!!

    • @SystemDemon
      @SystemDemon 3 ปีที่แล้ว +5

      These are blessing comments! David is my IT hero and my life is changing as well.
      I say David is making art, and we cant thank him enough!

  • @davidbombal
    @davidbombal  3 ปีที่แล้ว +6

    Legit TCP flows or hacking attacks? Can Wireshark help us to decode the flows and see if the traffic is malicious?
    // WIRESHARK FILE //
    Download here: www.dropbox.com/s/pvytdvkvxl8b41n/SYNScan_GeoIP_ChrisGreer.pcapng.zip?dl=0
    // MAXMIND //
    How to: wiki.wireshark.org/HowToUseGeoIP
    Maxmind: www.maxmind.com/en/home
    // MY STUFF //
    www.amazon.com/shop/davidbombal
    // SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: twitter.com/davidbombal
    Instagram: instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    TH-cam: th-cam.com/users/davidbombal
    //CHRIS GREER //
    Udemy course: davidbombal.wiki/chriswireshark
    LinkedIn: www.linkedin.com/in/cgreer/
    TH-cam: th-cam.com/users/ChrisGreer
    Twitter: twitter.com/packetpioneer
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

  • @warrioratthewall1969
    @warrioratthewall1969 2 ปีที่แล้ว +2

    I like when you ask questions David. It's often something I'm wanting to ask, or sometimes something I should be asking but didnt even ask in my mind. Thanks again!

  • @Pay-No-Mind
    @Pay-No-Mind ปีที่แล้ว +1

    In response to the question, I'd prefer if you wrote/noted the questions for later and just let the person talk because you never know what cool lessons/tips/stories you missed out on because their flow/train of thought was stopped.
    Just pick up at the end
    LOVE the content! This has me busy and working towards real goals out of deep pit of depression I've been in for years, thank you David :)

  • @piotrwikarski9401
    @piotrwikarski9401 3 ปีที่แล้ว

    Thank you guys for collaborating. Chris Greer is amazing. Strange that I never came across him before. Thanks again!

  • @CyberNancy
    @CyberNancy 3 ปีที่แล้ว +10

    Solid content. Knowing what normal/innocuous traffic patterns look like helps you identify the suspicious traffic patterns.
    Chris's focus on TTL, window size, and sequence numbers is a really great example of how a seasoned analyst approaches pcap.

  • @itech_live
    @itech_live 3 ปีที่แล้ว +1

    I came across to this demo, it was really helpful for me to learn about Maxmind and integrated to my Wireshark. Thanks to you and your host for put time on making this video.

  • @TheStsparrow
    @TheStsparrow 3 ปีที่แล้ว +2

    Something to note: Industrial control system protocols commonly utilize 20 byte header lengths. It's done for efficiency. But arguably they don't generally run on TCP port 80.... and hopefully not over the internet.
    Great video guys

  • @Alain9-1
    @Alain9-1 3 ปีที่แล้ว +8

    please don't let down those long video version i've enjoyed them a lot and waiting for more ( TCP/IP, scapy, Linux ...) 🔥🔥

  • @sergeyshevtsov5125
    @sergeyshevtsov5125 3 ปีที่แล้ว +2

    David, every video you make is non trivial and some kind of fantastic. Thanks Chris for sharing knowledge!

  • @rusnakhraj7401
    @rusnakhraj7401 2 ปีที่แล้ว

    For me I prefer if u r asking question around because it gives us more information and it can help us understand topic better from other point of view. And I see that you have really good questions from student point of view David.

  • @amirchegg
    @amirchegg 3 ปีที่แล้ว +6

    As always, Thank you David!
    If you can please do a walkthrough series on Kali Linux Tools, that would be awesome.
    There was a video where you showed us how to use Wifite properly, how to configure it and also how to troubleshoot common problems (which i think is a phenomenon! No-one bothers itself to explain how to solve those problems, but you did make a separate video just to show us how to fix problems we all have encountered while working with that tool).
    Sience many people want to learn ethical hacking and this channel is by far my favorite resource, making a series of videos explaining each and every tool that is shipped with Kali has a really good potential.
    Also, the way you explain things is absolutely incredible and makes difficult things to be super easy to grasp. Thats the main reason why im asking you for this!
    Ive got nothing more to say and im really looking forward to see those videos!

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thank you. Great suggestion 😄

  • @dwaynesudduth1028
    @dwaynesudduth1028 3 ปีที่แล้ว +1

    Fantastic content once again, proving that you are a top-tier content creator for IT. Thank you and thank you Chris Greer!!

  • @GenXpress
    @GenXpress ปีที่แล้ว

    Thank you, David, and in this video Chris too. Your content is great, and I been following you for a while....Keep it up and keep it coming :)

  • @tommyd22277
    @tommyd22277 3 ปีที่แล้ว +1

    David this was fantastic! I enjoyed that a lot. Keep bringing the excellent content. I really appreciate you!

  • @jaimerosariojusticia
    @jaimerosariojusticia 3 ปีที่แล้ว +7

    Questions. Always ask, even if is a "dumb" one. The answer is what matters and what is needed.
    Great video (even the first 5 min are good enough)
    Thanks again David Bombal.

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thank you. I'll do that 😄

  • @marcorossi2664
    @marcorossi2664 ปีที่แล้ว

    Grazie David per i contenuti che divulghi....io sono Italiano e ti seguo da un po...mi hai aperto un mondo....😊

  • @samjones4327
    @samjones4327 2 ปีที่แล้ว

    Another awesome video!!! Thank you guys for showing us how to read and interpret the packet capture in wireshark!!! I have a new and easier understanding of what I am looking at! Supurb explanation! Now I have a new toy through GOIP!! I would love to see NMAP in action in wireshark! Thanks David and Chris! Cheers!

  • @skriptak6308
    @skriptak6308 2 ปีที่แล้ว

    I can't tell if that's just David's personality, but I notice he's one of those people that talk over you in a Convo lol ... Chris can't get out a full sentence before David interrupts him ..either way both of these guys are brilliant as well as the video ...love it !

  • @majiddehbi9186
    @majiddehbi9186 3 ปีที่แล้ว

    Such pleasure its real chrismus to have u here guys its so instructive God bless u

  • @brianturney2124
    @brianturney2124 2 ปีที่แล้ว

    This is great. I love it when you ask lots of questions. I am usually asking the same ones in my head. Perfect!

  • @patrickilunga3312
    @patrickilunga3312 3 ปีที่แล้ว +1

    Thanks David after 6 months moving in US I got job RTP because I am also CCNA certified.

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว +1

      Huge congratulations Patrick! Well done!

  • @jacobhenriksen2324
    @jacobhenriksen2324 3 ปีที่แล้ว +1

    Love these videos! Could watch for hours

  • @Denverbi11
    @Denverbi11 3 ปีที่แล้ว +1

    Great video. Great Collaboration. I would really enjoy the nmap analysis.

  • @vyasG
    @vyasG 3 ปีที่แล้ว

    Thank you David and Chris for this amazing video. Very useful content.

  • @albanselaj733
    @albanselaj733 3 ปีที่แล้ว

    Thanks, David and Chris! Amazing content that helps us a lot in our everyday work!

  • @naesone2653
    @naesone2653 ปีที่แล้ว

    Bunch of questions is great david thank you

  • @gamershubke6982
    @gamershubke6982 3 ปีที่แล้ว +1

    Love your videos since day one I have learnt alot from you continue doing this great work 💪

  • @planetbobful
    @planetbobful 3 ปีที่แล้ว +1

    Great vid - lekker man!
    Love the Blue Hat training vids - greatly appreciated!

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Happy to hear that :)

  • @marcsuhling9317
    @marcsuhling9317 3 ปีที่แล้ว

    wow this is so interesting to watch and learn from the pros. thanks david for this video.

  • @aquadir2830
    @aquadir2830 3 ปีที่แล้ว

    Thank you so much David.. I'm a big fan of yours..
    Happy merry Christmas 🎄..

  • @nallachi2913
    @nallachi2913 3 ปีที่แล้ว +1

    Nice conversation both of you chris and DB❤️❤️❤️ are marvelous stuff giving persons

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thank you. Lots of fun talking with Chris about Wireshark 😄

  • @kjetilandreedstrm1678
    @kjetilandreedstrm1678 3 ปีที่แล้ว +3

    Hi! Great video! I was blown away over this!
    But it might be just me that is a complete noob. I just find a TCP-handshake file with 15 packets in the WireShark-link above? Should it not be the complete file from the attack Chris is using in the video?

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thanks. Please try this link: davidbombal.wiki/tcphackers1 - looks like I made a mistake :(

    • @kjetilandreedstrm1678
      @kjetilandreedstrm1678 3 ปีที่แล้ว

      @@davidbombal Hm. It looks like this link is directing to the same file as the other link??

    • @zioleo9093
      @zioleo9093 3 ปีที่แล้ว

      Same File , Just 15 packets.

  • @tmusic99
    @tmusic99 ปีที่แล้ว

    Very interesting. I have done a lot of statistical analysis in other domains. Would love to see more statistical analysis examples in Wireshark. And how to export data, filtered or not filtered, to a statistical analysis package.

  • @jointherevolution5577
    @jointherevolution5577 2 ปีที่แล้ว

    Very good work mate! helped a lot with a uni assignment!

  • @tarrylim778
    @tarrylim778 3 ปีที่แล้ว

    Excited next video with how nmap scan

  • @glenp42
    @glenp42 3 ปีที่แล้ว +2

    Q: Can we get copies of the wireshark profiles used?

  • @Ak4sh07
    @Ak4sh07 3 ปีที่แล้ว +1

    Love You David Bombal

  • @fritzbiederstadt4869
    @fritzbiederstadt4869 8 หลายเดือนก่อน

    I can imagine a lot more utility then just for attacks. Makes me think of EtherPeek IP Maps, the old sniffer pro ip matrix or Skitter application that is or used to be available via CAIDA - pretty cool. Did not know that feature set was available for Wireshark

  • @faran_siddiqui-d3t
    @faran_siddiqui-d3t 3 ปีที่แล้ว

    David and chris are the best

  • @avjyots2601
    @avjyots2601 2 ปีที่แล้ว

    Amazing analysis, thanks 👍

  • @ranganathannandakumar4463
    @ranganathannandakumar4463 ปีที่แล้ว

    This is GOLD! Thank you!

  • @tahersadeghi6773
    @tahersadeghi6773 ปีที่แล้ว

    Hey Chris. In this video, you mention a low number in a suspicious 34000 range. Is this number randomly chosen by the server, browser, or person initiating the packet? and what if this number was in the high number range?

  • @batreilangrynjah2526
    @batreilangrynjah2526 3 ปีที่แล้ว

    thank you David for this I learned a lot ..want some more videos like this

  • @Andrew-mh6cl
    @Andrew-mh6cl 3 ปีที่แล้ว

    Congrats sir we ill reach soon 1million best wishes master. ❤️❤️❤️❤️❤️❤️❤️

  • @smokestudio1408
    @smokestudio1408 3 ปีที่แล้ว +1

    Really interesting stuff ☺️

  • @anthonyjohnson2607
    @anthonyjohnson2607 3 ปีที่แล้ว

    keep on asking questions david, we all have the same questions!

  • @killerx8902
    @killerx8902 3 ปีที่แล้ว

    Great stuff and I vote for nmap

  • @fifthamendment1
    @fifthamendment1 ปีที่แล้ว

    If the TTL number is close, would it not mean that the source is from the same location? Perhaps the hops were changed up a bit such as sent through various VPNs?

  • @mouridmostapha9378
    @mouridmostapha9378 3 ปีที่แล้ว

    You the best david keep 🔥❤

  • @itsme7570
    @itsme7570 3 ปีที่แล้ว

    Sometimes David asks very basic questions but I guess it doesn't hurt

  • @Whit3hat
    @Whit3hat 7 หลายเดือนก่อน

    Ask away David, most cases what I was thinking thx

  • @ThePumbaadk
    @ThePumbaadk 3 ปีที่แล้ว

    What a great video, very nice 👍🏻

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thank you very much!

  • @joerockhead7246
    @joerockhead7246 11 หลายเดือนก่อน

    more Chris. more Chris. more Chris.

  • @gilbertohernandez9223
    @gilbertohernandez9223 3 ปีที่แล้ว

    Do you have a podcast by chance? I enjoy hearing you talk about anything computers related.

  • @omkhard1833
    @omkhard1833 3 ปีที่แล้ว

    Great Video Sir David ....

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว +1

      Glad you liked it!

  • @scottsparling2591
    @scottsparling2591 2 ปีที่แล้ว

    so, if UDP is connection-less, but QUIC is happening over UDP, AND has a connection ID and session ID (TLS), are we now to consider UDP in some cases connection oriented, or just consider QUIC connection oriented? I hope my question makes sense to others.

    • @vivekkrishnan9794
      @vivekkrishnan9794 ปีที่แล้ว

      From my understanding, quic is a protocol with connection oriented properties running over udp. UDP itself is not connection oriented

  • @symshark
    @symshark 3 ปีที่แล้ว

    The trace file in the download link only contains the TCP Handshake with 15 packets. Is the trace file used in this video available to download?

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว +1

      Please try again using this link: davidbombal.wiki/tcphackers1 - NOTE please that your browser may cache the incorrect link so you may need to use a private / incognito window or different browser if it doesn't work for you

  • @Ak4sh07
    @Ak4sh07 3 ปีที่แล้ว +1

    Great Content

  • @RayzDEV
    @RayzDEV 3 ปีที่แล้ว

    Thanks for video :) very informative.

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Glad it was helpful!

  • @majiddehbi9186
    @majiddehbi9186 3 ปีที่แล้ว

    One more question for Chris what's u re idealy profile in whshark in order to get a max of infos when we try to track the wierd packets thx

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      I'll ask Chris to cover Wireshark profiles in another video 😄

    • @majiddehbi9186
      @majiddehbi9186 3 ปีที่แล้ว

      @@davidbombal GOd bless u David and have wonderful Christmas with all u re be loved ones

  • @groovetrain397
    @groovetrain397 3 ปีที่แล้ว +1

    Ok thats great guys, so how do we block it!??

  • @KevinCrabb
    @KevinCrabb 3 ปีที่แล้ว

    Hi, David and Chris, I'm having a hard time making it work on my Windows version of Wireshark. I downloaded it for MMDB but it was formatted in tar.gz not .mmdb. So I formatted it to .mmdb, point it to my path folder, restarted Wireshark but no luck. Is there something I'm missing?

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว +1

      There was a problem with the download link. Please try downloading again using the Dropbox link in the video description. It is a zip file that you need to download

  • @DevrajSingh-rs7fn
    @DevrajSingh-rs7fn 3 ปีที่แล้ว +1

    Hi
    Big fan of you and your videos

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว +1

      Thank you so much 😀

  • @SuperPrabhdeepsingh
    @SuperPrabhdeepsingh 3 ปีที่แล้ว

    what a video!!
    Go for nmap for the next video

  • @trevorhenrytrey
    @trevorhenrytrey 3 ปีที่แล้ว

    How do you stop the traffic once you notice this is not normal traffic. Or it's not real time analysis

  • @danynite9736
    @danynite9736 3 ปีที่แล้ว

    Hello David I have a problem with Kali Linux in VMBox. When I use firefox, my CPU is 100% overloaded . What can I do against it?

  • @SOC_Pavi
    @SOC_Pavi 3 ปีที่แล้ว

    Hello David,
    Seems the pcap file that was uploaded to Dropbox only showing 15 packets. I not applied any filters. Could you please
    check and assist on this.

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Please try this link: davidbombal.wiki/tcphackers1

    • @zioleo9093
      @zioleo9093 3 ปีที่แล้ว

      @@davidbombal Same 15 Packets only. 😢

    • @SOC_Pavi
      @SOC_Pavi 3 ปีที่แล้ว

      @@davidbombalOnly 15 packets in the PCAP file

  • @jackjohn8323
    @jackjohn8323 3 ปีที่แล้ว

    Can you share the link to PCAP file please. The one shared only has the Videos but not PCAP

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thanks. I've fixed the link. Please download again. davidbombal.wiki/tcphackers1

  • @mmaranta785
    @mmaranta785 ปีที่แล้ว

    Wonderful!

  • @Firoz900
    @Firoz900 3 ปีที่แล้ว

    Great. Thank you guru.

  • @refaiabdeen5943
    @refaiabdeen5943 2 ปีที่แล้ว

    Cheers Mate.

  • @adolfor5427
    @adolfor5427 3 ปีที่แล้ว

    Mannnn, this is just cool

  • @theconfusedhamster
    @theconfusedhamster 3 ปีที่แล้ว +1

    Imagine heart and comment from Devid Sir

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      You got it! Now what?

    • @theconfusedhamster
      @theconfusedhamster 3 ปีที่แล้ว

      @@davidbombal now I am Gonna Fall in love for You

  • @ashersilver7388
    @ashersilver7388 2 ปีที่แล้ว

    I havnt watched the whole video. But yes, ASK AWAY!!!

  • @chris7691
    @chris7691 3 ปีที่แล้ว

    LOTS OF QUESTIONS

  • @JarppaGuru
    @JarppaGuru 2 ปีที่แล้ว

    3:50 now give compare very popular website are they 1 second part.

  • @technoman9926
    @technoman9926 3 ปีที่แล้ว +1

    Print ("hello David")

  • @sayedislam8117
    @sayedislam8117 3 ปีที่แล้ว

    Love from 🇧🇩

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thank you and welcome!

  • @Andrew-mh6cl
    @Andrew-mh6cl 3 ปีที่แล้ว

    First sir. Good evening ❤️❤️❤️❤️❤️

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว +1

      Good evening! And thank you for your support!

    • @Andrew-mh6cl
      @Andrew-mh6cl 3 ปีที่แล้ว

      @@davidbombal always you are my inspiration, role model,my Master 😘😘😘😘

  • @UrRealestCritic
    @UrRealestCritic 3 ปีที่แล้ว

    Can I use witeshark on the new M1 MacBook?

  • @ArSiddharth
    @ArSiddharth 3 ปีที่แล้ว

    Sir I'm your Big fan

  • @omharwalkar4868
    @omharwalkar4868 3 ปีที่แล้ว +2

    Sir how to hack any Android phone by sending image file. It's possible

    • @shlokjhunjhunwala7082
      @shlokjhunjhunwala7082 3 ปีที่แล้ว +1

      Is it possible?

    • @hack4peace
      @hack4peace 3 ปีที่แล้ว

      Yes

    • @raghavendraraaghu7908
      @raghavendraraaghu7908 3 ปีที่แล้ว

      No it's not possible since we can't have a backdoor like processing the payload as a backdoor when the img is opened if I'm not wrong!

    • @omharwalkar4868
      @omharwalkar4868 3 ปีที่แล้ว

      @@shlokjhunjhunwala7082 but how

    • @omharwalkar4868
      @omharwalkar4868 3 ปีที่แล้ว

      @@hack4peace but how

  • @fahadbawazir1771
    @fahadbawazir1771 3 ปีที่แล้ว

    David sir, I like that..

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Really happy to hear that

  • @sohilshrestha3089
    @sohilshrestha3089 3 ปีที่แล้ว

    how to stop my terminal from saving history in kali linux 2021.4

  • @ArSiddharth
    @ArSiddharth 3 ปีที่แล้ว

    Nice video

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thank you very much!

  • @mohamedaymenzebouchi
    @mohamedaymenzebouchi 3 ปีที่แล้ว

    Yeh, ask questions

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Thanks. I'll do that 😄

  • @vikpa1211
    @vikpa1211 2 หลายเดือนก่อน

    I think machine learning algorithms can detect those types of patterns and malicious traffic in real time

  • @Thriller627
    @Thriller627 3 ปีที่แล้ว

    Cheers! P;S. Keep on asking questions.. d ; } #DavidBombal

  • @juanrodriguez825
    @juanrodriguez825 3 ปีที่แล้ว +1

    Nmap

  • @abdulrahmanfaisal288
    @abdulrahmanfaisal288 3 ปีที่แล้ว

    Keep going

  • @julianllouve4835
    @julianllouve4835 2 ปีที่แล้ว

    you the best

  • @tyalva1814
    @tyalva1814 2 ปีที่แล้ว

    phone verification not working on discord

  • @yeteldonn4649
    @yeteldonn4649 2 ปีที่แล้ว

    thx u.

  • @originals2747
    @originals2747 3 ปีที่แล้ว

    informative

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว

      Glad you enjoyed the video 😄

  • @ArSiddharth
    @ArSiddharth 3 ปีที่แล้ว

    I have a question,
    I'm a beginner, And I do not understand where should I start, from where should I study? I don't understand anything.....
    Love❤️ from india 🇮🇳

    • @davidbombal
      @davidbombal  3 ปีที่แล้ว +1

      Network+ or CCNA are a great way to start learning basics. Watch this video for more tips: th-cam.com/video/SFbV7sTSAlA/w-d-xo.html

    • @ArSiddharth
      @ArSiddharth 3 ปีที่แล้ว

      @@davidbombal ohh men, thanks a lot, I didn't think you would reply to my comment ,Thanks sir, ♥️♥️

  • @MrDullBull
    @MrDullBull 3 ปีที่แล้ว

    Greetings from Russia! You put us on the map! LOL

  • @alapanroy1114
    @alapanroy1114 ปีที่แล้ว

    I want question ans conversion

  • @fairplay8347
    @fairplay8347 3 ปีที่แล้ว

    Sir
    Love from India
    Iam a CCNP student
    Should I learn python for future

  • @fahadbawazir1771
    @fahadbawazir1771 3 ปีที่แล้ว

    Good