Skip to content

Repository files navigation

PHÂN TÍCH GIAO THỨC MẠNG BẰNG WIRESHARK

Mục tiêu

  • Capture lưu lượng mạng bằng Wireshark.
  • Phân tích ARP, ICMP, DNS, TCP, UDP, HTTP, HTTPS và DHCP.
  • Sử dụng Display Filter để lọc gói tin.

Yêu cầu

  • Wireshark
  • Máy tính có kết nối mạng
  • CMD/Terminal và trình duyệt

1. Cài đặt Wireshark

Windows

  1. Tải Wireshark từ https://www.wireshark.org/
  2. Cài đặt và chọn cài thêm Npcap.

Ubuntu

sudo apt update
sudo apt install wireshark
sudo dpkg-reconfigure wireshark-common
sudo usermod -aG wireshark $USER

2. Capture Packet

  1. Mở Wireshark.
  2. Chọn card mạng đang sử dụng.
  3. Nhấn đúp để bắt gói tin.

3. Phân tích ARP

arp

Thực hiện:

ping 192.168.1.1

Quan sát ARP Request và ARP Reply.

4. Phân tích ICMP

icmp
ping google.com

Quan sát Echo Request và Echo Reply.

5. Phân tích DNS

dns
nslookup google.com

Quan sát Standard Query và Standard Query Response.

6. Phân tích TCP

tcp

Mở một website và quan sát TCP Three-Way Handshake: - SYN - SYN/ACK - ACK

7. Phân tích HTTP

Truy cập: http://neverssl.com

Filter:

http

Quan sát GET, Response 200 OK và các Header.

8. Phân tích HTTPS

Truy cập: https://google.com

Filter:

tls

Quan sát Client Hello, Server Hello, Certificate và Encrypted Application Data.

9. Phân tích UDP

udp

Quan sát Source Port, Destination Port và Length.

10. Phân tích DHCP

Filter:

bootp

Windows:

ipconfig /release
ipconfig /renew

Quan sát Discover → Offer → Request → ACK.

11. Lưu kết quả

Chọn File → Save As và lưu với tên Lab_Wireshark.pcapng.

Kết luận

Sau bài thực hành, người học có thể: - Capture và phân tích gói tin. - Hiểu hoạt động của các giao thức mạng phổ biến. - Sử dụng Wireshark để hỗ trợ quản trị và xử lý sự cố mạng.

Releases

Packages

Contributors