Page cover

TShark

Reading PCAP Files

How many packets are in the dns.cap file?

╭─hnl@hnl ~/Desktop/ctf/tryhackme/tshark  
╰─➤  tshark -r dns.cap| wc -l                                                                                                           130 
38

How many A records are in the capture? (Including responses)

╭─hnl@hnl ~/Desktop/ctf/tryhackme/tshark  
╰─➤  tshark -r dns.cap -Y "dns.qry.type == 1" | wc -l
6

Which A record was present the most?

╭─hnl@hnl ~/Desktop/ctf/tryhackme/tshark  
╰─➤  tshark -r dns.cap -Y "dns.qry.type == 1" -T fields -e dns.qry.name
www.netbsd.org
www.netbsd.org
GRIMM.utelsystems.local
GRIMM.utelsystems.local
GRIMM.utelsystems.local
GRIMM.utelsystems.local

DNS Exfil

How many packets are in this capture?

How many DNS queries are in this pcap? (Not responses!)

What is the DNS transaction ID of the suspicious queries (in hex)?

What is the string extracted from the DNS queries?

What is the flag?

Last updated