- Capture lưu lượng mạng bằng Wireshark.
- Phân tích ARP, ICMP, DNS, TCP, UDP, HTTP, HTTPS và DHCP.
- Sử dụng Display Filter để lọc gói tin.
- Wireshark
- Máy tính có kết nối mạng
- CMD/Terminal và trình duyệt
- Tải Wireshark từ https://www.wireshark.org/
- Cài đặt và chọn cài thêm Npcap.
sudo apt update
sudo apt install wireshark
sudo dpkg-reconfigure wireshark-common
sudo usermod -aG wireshark $USER- Mở Wireshark.
- Chọn card mạng đang sử dụng.
- Nhấn đúp để bắt gói tin.
arp
Thực hiện:
ping 192.168.1.1Quan sát ARP Request và ARP Reply.
icmp
ping google.comQuan sát Echo Request và Echo Reply.
dns
nslookup google.comQuan sát Standard Query và Standard Query Response.
tcp
Mở một website và quan sát TCP Three-Way Handshake: - SYN - SYN/ACK - ACK
Truy cập: http://neverssl.com
Filter:
http
Quan sát GET, Response 200 OK và các Header.
Truy cập: https://google.com
Filter:
tls
Quan sát Client Hello, Server Hello, Certificate và Encrypted Application Data.
udp
Quan sát Source Port, Destination Port và Length.
Filter:
bootp
Windows:
ipconfig /release
ipconfig /renewQuan sát Discover → Offer → Request → ACK.
Chọn File → Save As và lưu với tên Lab_Wireshark.pcapng.
Sau bài thực hành, người học có thể: - Capture và phân tích gói tin. - Hiểu hoạt động của các giao thức mạng phổ biến. - Sử dụng Wireshark để hỗ trợ quản trị và xử lý sự cố mạng.