Cyber Forensic Lab Assignment 1-4
Cyber Forensic Lab Assignment 1-4
Topology
WRT 30ON
neleS Routey
Cable Modem P7
pC- PT Cloud- PT
PC Tntewnet o
Laptop-P7 Sewe pT
Lap topD Ciso Om
Addresai Tasle
LP Addrey Swont Mata Dyaut ate ao ay
Deviee Interface 192- l68.0, |
(92-16B0) 2S 2SS.2SS.b
wles LAN
Ro ute
iees Lnteenet DH CP
ROnteu 2SS. 25S.253. o
202- ,?-220-22o
C isco Com Rhent D
Semwey
DHCP
Veity Connetulkg
ue and cloae Packet Tracen.
D Sauwe the
CONLUSION
OI MooEL >
(osr) model dee eribes
Inteaconneeton to communicate
(he open sytem ystem
Seuen Cayeas hat comnputer
bare On the concept
netooh , It is into 3even
a communication ystem
a
Spliting p
albstract cayeS
Sec >
LAB AssIGNn\ENT 2
ExPERIM ENT 2i- 0ieshaLk as a Neloosk Pooto co
Analyze
PART’1 - ORESHARK EN VIRONMENT
vaeerous command ?
gecteon menu ba enales
captae e edit 7
an 'detination"?
A RIO) ypes of *s0unce'
t7
adres n
locate "sownoe"and 'letenalisn'3
netooy k
he pa chet detaies Pane ohen analyzing
trafic.
genden or
oneye packek s gent
owce port ncemben asoclated
D SoCe Pot ’
poces hat
generated the packet.
(B) DESTINAeON AopRESS
dres
AddeK ’ Thes -ts fhe Te ad
ODestnation LP eent
cohich he packee s
device
the
Ag9ocoled
(i) Destnalion Port ’ detinalion olevibe
n he
applcation or proces
0ilh the
the fixt echo equert
belou,
Analyreeano and
reply and omplete he fae
and
First Echo first Echo
Request Reply
frame Number 3040q 30854
|2409:4089:le18: 2404:686D : 46D4:
Source Te Address a032: 2Sab: as4: Bo3:: 2604
ze4 b3ct
2404: 686D 2 46042409:4 D89:le18 :Q032:
Destinaton TP Addres B03:: 2604 35aG i abyy:2e g4
b3et
TCMP pe Vaue 128 129
Conclusion
this capeiment, we fomi ar2ed nth Wireshark appuation
Thouh Qt and perfoh TeP
and petomed Pbu capture ahcd analyas 4it
Hand shaking
Netgtat|TPcone he gewiceg
Gome
(Q) ote dousn tne name
ODNs Cçent
Aug OTP Helper
o Embedded Moce Fa Ple Syne telper
coent gewice 7
Q T he DHCP
lient Bewice es
yes, DHCP
SewiceR hat
3) Note doon the Netroork Jrspectio
genvice
Delenden Antivis
As OMieosoft
Nelloqon Pg and Plug
O Seswiee
Oallet
O Véntual Duk the
System,
out ne TP add'
poonfg
|42: 168.57- 222
OTP,y Addres (ec74db9:995: SSA
+ qeaB:
Addes 2M09: u0e9 2d82:
() TPvb
Pnd mac aldek
44-12- B3-B3 - B 3 7
?
atwe
ae
(6) tteo mangwrelen LAN Adapte, oi-Pi
'1
EXPwRER
SySNTeRNALS PROCess
Set,
ePU, Prwate eytes
(aD fnd the PID, name -for tne
deseriptsRn , compang
Procew aystomfU<o.0, PID Slb
-2436 k
Put Byte = 304Ok
gmes.ee PIP S76
PD (062
O6)364
O62369
IPCONFlG
Ote deon he gubnet mak B Local conmpute
25S.2ss.25S.O
|92 (6.S7 6O
A Cocal
ase to
(Q)ere
suczenfallyt ?
Yes, 0th local
IP addre
You abe to
Q Dene auccenht
DN3
(As) Yes, wh
TRACERT awilale cot tace t
all fhe option
to hostname.
OPTION Don't eowe adades
seaHch fo taget
no. o hops 40 host -eR
masm youte along
Coose gounee m'uliceconds
for each
o i t toneou
race ord-trp alh
-R astar
Sowice
LAB AsSTGNMeNT ’4
TCP DUMPoume cAr
menege
Ar TCP
Ne
1
UDP
Protoo
N SOURCe Datonal ten
192- 168. S222 SS. |O-80.L
CSVNJ
Dest(NAT (ON PROTOcoL 44424 ’ 448
T
DESTINANON
SouRCE
4u3>4q42
seqsD,Ack|
wn64768
Conne'on tesunnale ?
CeN, AcI
4942 3 ’443
Tme SoURCe
2023)2-S 2u09 -g4:2d ob4ot: edes i edbc: qau
LAKHANI
KAUSHIK
NAMe ’
ReG No> oyLo2OO2
3ec ’CSIT D