Chris Greer
How DNS Works Under the Hood (Packet by Packet)
updated
In this video we interview the creator of Wireshark - Gerald Combs. He tells us about Wireshark's new baby brother, why it was needed, what visibility gap it fills, and how to download it.
You can install Stratoshark by going to stratoshark.org
Note you can download a sample scap (note, not pcap!) and follow along as Gerald guides us through this new syscall/log analyzer!
Stratoshark Wiki: wiki.wireshark.org/Stratoshark
Thanks Gerald and congrats to you and the Wireshark Foundation for this new release.
Want more packets?
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
== Social ===
LinkedIn - linkedin.com/in/cgreer
X Twitter - twitter.com/packetpioneer
== Chapters ==
0:00 Welcome Gerald
0:52 Announcing Stratoshark
1:56 What are system calls?
2:23 Why "Stratoshark"?
3:34 Where it captures
4:41 How to get Stratoshark
5:28 Stratoshark Demo!
7:52 What is next?
You know what to do packet people - download and follow along!
github.com/packetpioneer/youtube/blob/main/tls-handshake.pcapng
If you like, please let me know!! It helps. Really.
Want more packety goodness?
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
==Filter==
tcp.stream==${tcp.stream}
Add -1 or +1 to the end to go back or forward one stream.
Thanks to Sake Blok - https://www.SYN-bit.nl - who shared this filter at Sharkfest Europe 2024 in Vienna, Austria. For more information on Sharkfest and how to attend - sharkfest.wireshark.org
Link to pcap: github.com/packetpioneer/youtube/blob/main/tcp-sequencesample.pcapng
Link to profile: github.com/packetpioneer/profiles/blob/main/Chris-TCPPlain.zip
If you like this content, let me know by subbing!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Private Wireshark Training ==
Let's get in touch - https://packetpioneer.com/product/pri...
Download the packets here:
malware-traffic-analysis.net/2024/09/17/index.html (Thanks Brad!)
Password to unlock: infected_20240917
Best to analyze this pcap in an isolated VM. You've been warned.
Want more packets?
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Thank you to Brad Duncan for the pcap samples that I was not able to create on my own!
For professional inquiries please contact me at packetpioneer@gmail.com
The pcap shown on this video was taken from malware-traffic-analysis.net. Thanks Brad!
If you like this content, let me know by subbing!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
== Social ===
LinkedIn - linkedin.com/in/cgreer
X Twitter - twitter.com/packetpioneer
In this video, we’ll look at how you can still analyze quite a bit in encrypted TCP-based traffic. While encryption can make network analysis challenging, there are still valuable insights to be gained.
We will be using this pcap in the video so download and follow along.
github.com/packetpioneer/youtube/blob/main/tls-handshake.pcapng
If you like this content, let me know by subbing.
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
== Social ===
LinkedIn - linkedin.com/in/cgreer
X Twitter - twitter.com/packetpioneer
If you like this content, let me know by subbing!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
== Social ===
LinkedIn - linkedin.com/in/cgreer
X Twitter - twitter.com/packetpioneer
To learn more check out my Udemy course - bit.ly/udemywireshark
For more Wireshark check out my Udemy course! bit.ly/udemywireshark
Learn more - bit.ly/udemywireshark
If you like this content, let me know by subbing!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
bit.ly/udemynmap
Don't mean to throw a commercial at you guys but you supporting me this way really helps me keep the channel going, so thank you to all who take the course!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
For more info on training or consulting engagements with Wireshark, Nmap, or other tools, check out my website at:
www.packetpioneer.com
Let's dig!
Get the pcaps here - malware-traffic-analysis.net/training-exercises.html
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Questions? Comments?
You know what to do below!
Chapters:
0:00 Intro
0:40 Get the PCAP
1:52 Victim's IP Address
3:48 Stolen Credentials
5:50 Decoding Base64 Logins
tryhackme.com/room/wiresharktrafficanalysis
You can also check out my TryHackMe Wireshark Filters room at:
tryhackme.com/jr/wiresharkfilters
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
0:00 Intro and Task 1
1:36 Task 2 - Nmap Scans
7:56 Task 3 - ARP Poisoning
15:46Task 4 - DHCP, NetBIOS, Kerberos
23:25 Task 5 - DNS and ICMP
28:23 Task 6 - FTP Analysis
33:18 Task 7 - HTTP Analysis
40:36 Task 8 - Decrypting HTTPS
46:21 Task 9 - Bonus, Cleartext Creds
48:05 Task 10 - Firewall Rules
Follow along as Ben shows us how!
Like, share, subscribe if you think this is good content!
// Links and things //
Nahamsec Channel - youtube.com/@UCCZDt7MuC3Hzs6IH4xODLBw
Nahamsec Website - nahamsec.com
Hacker 101 - hacker101.com
TryHackMe - tryhackme.com
Intro to Bug Bounty - udemy.com/course/intro-to-bug-bounty-by-nahamsec
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Chapters:
0:00 Welcome Nahamsec!
0:32 Active Recon
1:10 Let's Hack Cisco
4:10 First steps
6:15 Anyone can do this
8:08 What next?
packetpioneer.com
Like, share, subscribe if you think this is good content!
// Links and things //
Nahamsec Channel - youtube.com/@NahamSec
Nahamsec Website - nahamsec.com
Hacker 101 - hacker101.com
TryHackMe - tryhackme.com
VulnHub - vulnhub.com
Intro to Bug Bounty - udemy.com/course/intro-to-bug-bounty-by-nahamsec
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Chapters:
0:00 Welcome Nahamsec!
0:32 Top Three Vulns
1:23 How does SSRF work?
4:00 Can we see this in Wireshark?
5:28 How can I learn more?
6:55 What is next?
packetpioneer.com
Here is a link to the pcap I use in the video - packetpioneer.com/wp-content/uploads/tcp-completeness-chrisgreer.pcapng.zip
Link to the Wireshark TCP Analysis writeup - wireshark.org/docs/wsug_html_chunked/ChAdvTCPAnalysis.html
Want some hands on with TCP? Consider taking one of my courses.
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
In this series, Nahamsec himself joins Chris on a journey to learn how to hack websites for vulnerabilities. Whether the goal is to project our own environment, learn Bug Bounty, or sheer interest, web hacking is becoming an important skill to learn and master.
Let's do this packet people! Please like, share, subscribe if you like this content!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
// Links and things //
Nahamsec Channel - youtube.com/@NahamSec
Nahamsec Website - nahamsec.com
Intro to Bug Bounty - udemy.com/course/intro-to-bug-bounty-by-nahamsec
TCP for Hackers - training.defcon.org/pages/def-con-trainings-bellevue-april-2023
Chapters:
0:00 Welcome Nahamsec!
0:42 Why Learn Web Hacking?
1:23 Is this legal?
2:28 Top Three Skills to Learn Web Hacking
4:43 Can I get a job?
packetpioneer.com
If you like this content, let me know by subbing!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
0:00 Network RTT
0:33 TCP Options
1:19 Port Numbers
In this video we walkthrough the Packet Operations room on TryHackMe. This room is a part of the SOC Analyst 1 path which covers network and packet analysis with a variety of tools including Wireshark. tryhackme.com/room/wiresharkpacketoperations
Also, for more practice, check out my free Wireshark Filters Room: tryhackme.com/jr/wiresharkfilters
Register for a free account and let's dig!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
For more practice with Wireshark Filters - check out my TryHackMe room!
tryhackme.com/jr/wiresharkfilters
// Links and Things //
openai.com
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Want to connect with me? Reach out at my website:
packetpioneer.com
Chapters:
0:00 OpenAI ChatGPT Intro
0:40 Subnet Filtering
2:42 TCP Port Range Filter
3:32 Regex Filters
5:00 TCP Retransmissions
5:40 PCAP Analysis Tips
TryHackMe Room Link: tryhackme.com/room/wiresharkthebasics
Register for a free account and let's dig!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
0:00 Intro and Task 1
1:27 Task 2 - Tool Overview
3:40 Task 3 - Packet Dissection
8:08 Task 4 - Packet Navigation
16:35 Task 5 - Packet Filtering
19:45 Task 6 - Conclusion
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
For more information, check out David and Chris' Wireshark course on Udemy.
bit.ly/udemywireshark
#shorts
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
For more information, check out their Wireshark course on Udemy.
bit.ly/udemywireshark
#shorts
//Links and Things//
Wireshark 4.0 Release Notes: wireshark.org/update/relnotes/wireshark-4.0.0.html
Report issues or suggest features:
gitlab.com/wireshark/wireshark/-/issues
Sharkfest Europe 2022
sharkfesteurope.wireshark.org/register
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
== Shopping List ==
Rasp Pi - amzn.to/3eIBSSu
SD Card - amzn.to/3eReVwz
Pi Case - amzn.to/3BTE8jf
Samsung SSD - amzn.to/3xu3RMt
Netgear Switch - amzn.to/3UbSLW7
Headless Install of Raspberry Pi: youtu.be/rGygESilg8w
Want some Wireshark training? Consider taking one of my courses.
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
If you liked this video, I’d really appreciate you giving me a like and subscribing, it helps me a whole lot. Also don't be shy, chat it up in the comments!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
rfc-editor.org/info/rfc9293
Want some hands on with TCP? Consider taking one of my courses.
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
TryHackMe Room Link: www.tryhackme.com/jr/wiresharkfilters
Register for a free account and let's dig!
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
0:00 Intro
1:51 Task 2 - Protocol Filters
7:01 Task 3 - IP Filters
12:10 Task 4 - TCP Filters
18:53 Task 5 - DNS Filters
25:38 Task 6 - Special Operators
30:15 Task 7 - Putting It Together: Filtering for Scans
37:02 Filtering For Usernames/Passwords
43:17 Conclusion
tryhackme.com/jr/wiresharkfilters
Check it out, it is free to get an account and go through the room. Get that practice packet people.
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
It's been a busy summer of packet crunching, teaching, and conferences. What content will find its way to the channel and what is in store for the near future? Let's chat.
//Links and such//
tryhackme.com - register for free!
tryhackme.com/jr/wiresharkfilters - check out my Wireshark room.
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Comment below and tell me what you think!
How does the TLS handshake work? It all starts with the client hello. In this video we are going to dive into what information is sent to a server in this phase of the handshake and the beginnings of how an encrypted connection is set up.
====================
Download the pcap here:
github.com/packetpioneer/youtube/blob/main/tls-handshake.pcapng
====================
For a much deeper dive into the TLS handshake and how it works, check out my buddy Ed's Practical ▶TLS course: bit.ly/PN-TLS
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
0:00 Intro to TLS
0:27 The Handshake
1:04 The Client Hello
2:22 Version Negotiation
4:40 TLS 1.3 Extensions
6:01 Why wrong version?
6:34 Server Version
7:11 Cipher Suites
8:50 Server Name
9:40 Application Negotiation
Let's learn a quick tip of how to scan a pcap for suspect HTTP User Agents, which Malware sometimes uses to initiate requests.
Link to the pcap:
malware-traffic-analysis.net/2020/05/28/index.html
The password to unzip the file is "infected"
Tshark command:
tshark -r example.pcap -T fields -e http.user_agent | sort | uniq -c
In Powershell:
tshark -r example.pcap -T fields -e http.user_agent | sort -unique
// Contact Me //
LinkedIn: linkedin.com/in/cgreer
YouTube: youtube.com/c/ChrisGreer
Twitter: twitter.com/packetpioneer
Get the book ---- amzn.to/3OqP0ZL
Check out TryHackMe - Start with my Wireshark Room!
tryhackme.com/jr/wiresharkfilters
Want more packet stuff?
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Links above contain affiliate links where I will receive a small amount for any goods purchased. I thank you for clicking because it really helps to support me!!
0:00 Intro
0:53 Scoring
1:10 I Stink at Host Analysis
1:28 How did I Pass?
2:03 The Book
3:01 TryHackMe Helped!
3:36 Extra Tips to Pass
4:45 Final Thoughts
malware-traffic-analysis.net/2020/05/28/index.html
The password to unzip the file is "infected"
If you liked this video, I’d really appreciate you giving me a like and subscribing, it helps me a whole lot. Also don't be shy, chat it up in the comments!
Video for configuring GeoIP in Wireshark:
youtu.be/IlVppluWTHw
// Contact Me //
LinkedIn: linkedin.com/in/cgreer
YouTube: youtube.com/c/ChrisGreer
Twitter: twitter.com/packetpioneer
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Links above contain affiliate links where I will receive a small amount for any goods purchased. I thank you for clicking because it really helps to support me!!
0:00 Intro
0:48 DNS Filters
2:00 HTTP Requests/Replies
5:00 Using GeoIP
5:48 Exporting Usernames and Passwords
6:48 Exporting System Info
8:50 Extracting Hidden EXE Files
11:44 TLS Handshake Signatures
// Download the pcap here //
github.com/packetpioneer/youtube/blob/main/tcp-zerowindow-greer.pcapng
Got questions? Let's get in touch.
LinkedIn: linkedin.com/in/cgreer
YouTube: youtube.com/c/ChrisGreer
Twitter: twitter.com/packetpioneer
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Links above contain affiliate links where I will receive a small amount for any goods purchased. I thank you for clicking because it really helps to support me!!
0:00 Intro
0:21 PCAP Overview
1:10 What a Zero Window means
4:59 How to fix it
6:44 Learn more!
Got questions? Let's get in touch.
LinkedIn: linkedin.com/in/cgreer
YouTube: youtube.com/c/ChrisGreer
Twitter: twitter.com/packetpioneer
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
//TLS Course from Practical Networking//
Want to go deeper into TLS? Check out my buddy Ed's course:
classes.pracnet.net/courses/practical-tls?affiliate=GJoShn
Links above contain affiliate links where I will receive a small amount for any goods purchased. I thank you for clicking because it really helps to support me!!
0:00 Intro
0:28 TLS Client Hello
1:36 Fatal TCP Error
2:04 TLS Protocol Versions
2:46 Why TLS 1.0?
3:37 Conclusion
Let's dig into a pcap of a DHCP transaction. If you are in network engineering this is a service you will DEFINITELY troubleshoot at some point.
Download the pcap here github.com/packetpioneer/youtube/blob/main/dhcp.pcapng
Got questions? Let's get in touch - packetpioneer@gmail.com
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Links above contain affiliate links where I will receive a small amount for any goods purchased. I thank you for clicking because it really helps to support me!!
0:00 Intro
0:19 DHCP Overview
0:56 Discover
4:39 DHCP Options
5:59 Offer
7:31 Request
8:30 Ack
If you liked this video, I’d really appreciate you giving me a like and subscribing, it helps me a whole lot. Also don't be shy, chat it up in the comments!
What network tap is in my backpack? Here is one that won't break the bank!
amzn.to/3qdCfrn
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
For professional inquiries please contact me at packetpioneer@gmail.com
Links above contain affiliate links where I will receive a small amount for any goods purchased. I thank you for clicking because it really helps to support me!! Thank you!!
Download the pcap here and follow right along:
packetpioneer.com/wp-content/uploads/chrisgreer-protocols-and-ports.zip
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Thank you to wiki.wireshark.org/SampleCaptures and Johannes Weber for the pcap samples that I was not able to create on my own!
For professional inquiries please contact me at packetpioneer@gmail.com
//Downloads//
Download the Fingerprinting OS PCAPs and NMAP OS Database
packetpioneer.com/wp-content/uploads/nmap-OS-fingerprint.zip
You can also access the OS database in the /usr/share/nmap folder when installing nmap on a linux system.
//Links//
NMAP OS Fingerprinting - nmap.org/book/osdetect-methods.html
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
//Timestamps://
0:00 Intro
0:45 Running the OS Fingerprinting Scan
2:43 Analyzing the scan in Wireshark
4:57 How OS Fingerprinting Works
8:58 Using the NMAP OS Database
10:30 Analyzing ICMP Behavior
12:06 Conclusion
This is important info to know for anyone going for their Pentest+, CEH, OSCP, eJPT, CySA+, or just about any other Cybersecurity Cert.
Let's capture and really learn how NMAP does its thing.
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Timestamps:
0:00 Intro
0:45 Analyzing the Xmas Scan
3:15 Xmas Scan to Windows 10
5.51 How the Null scan works
7:31 Why run a Null/Xmas scan?
8:49 Conclusion
Let's capture and really learn how NMAP does its thing.
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Timestamps:
0:00 Intro
0:51 Stealth Scan Explained
3:10 The Stealth Options
4:19 The Full Connect Scan
6:36 When to use Stealth vs Connect Scan
====Download the pcap here ====
packetpioneer.com/wp-content/uploads/ip_fragmentation_greer.zip
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Timestamps:
0:00 Intro
1:06 IP Fragments Explained
1:50 Fragmentation Illustrated
3:36 Analyzing Oversize Pings
8:21 The "Do Not Fragment" Bit
10:05 Using Fragmentation with NMAP
14:52 IP Fragmentation Overvew
Hope this helps Packet People! Please like, share, subscribe!
Shout out to @NetworkChuck for always drinking coffee on his videos. Gave me the inspiration to put it into this one.
----------Download the pcap here-----------
packetpioneer.com/wp-content/uploads/TCP-Retrans-and-Seq-Analysis.pcap_.zip
// WIRESHARK TRAINING - Udemy//
▶Getting Started with Wireshark - bit.ly/udemywireshark
// WIRESHARK TRAINING - Pluralsight//
Check out the free 10-day trial of my hands-on courses on Pluralsight:
▶TCP Fundamentals with Wireshark - bit.ly/wiresharktcp
▶Identify Cyber Attacks with Wireshark - bit.ly/wiresharkhunt
▶TCP Deep Dive with Wireshark - bit.ly/virtualwireshark
//LIVE TRAINING COURSE//
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
Hope this helps Packet People! Please like, share, subscribe!
First - you have to register and download the GeoIP Lite Databases (Free):
dev.maxmind.com/geoip/geolite2-free-geolocation-data?lang=en
Then, point Wireshark to the databases, look up endpoints, then toss them out to a map. Boom! You're done.
Like this video? Then show it! Please smash like and share it with all your IT buddies. That really helps me out.
Other links n' stuff:
== More On-Demand Training from Chris ==
▶Getting Started with Wireshark - bit.ly/udemywireshark
▶Getting Started with Nmap - bit.ly/udemynmap
== Live Wireshark Training ==
▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
== Private Wireshark Training ==
Let's get in touch - packetpioneer.com/product/private-virtual-classroom
Special thanks to my cat, Pepé for his video-bomb!


