Is this an attack? Wireshark Packet analysis // SYN Attack

  Рет қаралды 63,891

David Bombal

David Bombal

Күн бұрын

Пікірлер: 184
@SpragginsDesigns
@SpragginsDesigns 2 жыл бұрын
Thank you for everything, David. After two years in college I was just hired last week as a remote Web and Mobile App Designer and Developer. Because I am also OSCP certified, it drastically raised my salary and the fun level of my position. And a lot of your courses are to thank for this; college is just for the paper or "degrees"."
@davidbombal
@davidbombal 2 жыл бұрын
That is awesome! Congratulations!!!
@SystemDemon
@SystemDemon 2 жыл бұрын
These are blessing comments! David is my IT hero and my life is changing as well. I say David is making art, and we cant thank him enough!
@warrioratthewall1969
@warrioratthewall1969 2 жыл бұрын
I like when you ask questions David. It's often something I'm wanting to ask, or sometimes something I should be asking but didnt even ask in my mind. Thanks again!
@piotrwikarski9401
@piotrwikarski9401 2 жыл бұрын
Thank you guys for collaborating. Chris Greer is amazing. Strange that I never came across him before. Thanks again!
@pistol0grip0pump
@pistol0grip0pump Жыл бұрын
In response to the question, I'd prefer if you wrote/noted the questions for later and just let the person talk because you never know what cool lessons/tips/stories you missed out on because their flow/train of thought was stopped. Just pick up at the end LOVE the content! This has me busy and working towards real goals out of deep pit of depression I've been in for years, thank you David :)
@itech_live
@itech_live 2 жыл бұрын
I came across to this demo, it was really helpful for me to learn about Maxmind and integrated to my Wireshark. Thanks to you and your host for put time on making this video.
@Alain9-1
@Alain9-1 2 жыл бұрын
please don't let down those long video version i've enjoyed them a lot and waiting for more ( TCP/IP, scapy, Linux ...) 🔥🔥
@CyberNancy
@CyberNancy 2 жыл бұрын
Solid content. Knowing what normal/innocuous traffic patterns look like helps you identify the suspicious traffic patterns. Chris's focus on TTL, window size, and sequence numbers is a really great example of how a seasoned analyst approaches pcap.
@TheStsparrow
@TheStsparrow 2 жыл бұрын
Something to note: Industrial control system protocols commonly utilize 20 byte header lengths. It's done for efficiency. But arguably they don't generally run on TCP port 80.... and hopefully not over the internet. Great video guys
@warrioratthewall1969
@warrioratthewall1969 2 жыл бұрын
Like BACnet?
@sergeyshevtsov5125
@sergeyshevtsov5125 2 жыл бұрын
David, every video you make is non trivial and some kind of fantastic. Thanks Chris for sharing knowledge!
@rusnakhraj7401
@rusnakhraj7401 2 жыл бұрын
For me I prefer if u r asking question around because it gives us more information and it can help us understand topic better from other point of view. And I see that you have really good questions from student point of view David.
@amirchegg
@amirchegg 2 жыл бұрын
As always, Thank you David! If you can please do a walkthrough series on Kali Linux Tools, that would be awesome. There was a video where you showed us how to use Wifite properly, how to configure it and also how to troubleshoot common problems (which i think is a phenomenon! No-one bothers itself to explain how to solve those problems, but you did make a separate video just to show us how to fix problems we all have encountered while working with that tool). Sience many people want to learn ethical hacking and this channel is by far my favorite resource, making a series of videos explaining each and every tool that is shipped with Kali has a really good potential. Also, the way you explain things is absolutely incredible and makes difficult things to be super easy to grasp. Thats the main reason why im asking you for this! Ive got nothing more to say and im really looking forward to see those videos!
@davidbombal
@davidbombal 2 жыл бұрын
Thank you. Great suggestion 😄
@jaimerosariojusticia
@jaimerosariojusticia 2 жыл бұрын
Questions. Always ask, even if is a "dumb" one. The answer is what matters and what is needed. Great video (even the first 5 min are good enough) Thanks again David Bombal.
@davidbombal
@davidbombal 2 жыл бұрын
Thank you. I'll do that 😄
@patrickilunga3312
@patrickilunga3312 2 жыл бұрын
Thanks David after 6 months moving in US I got job RTP because I am also CCNA certified.
@davidbombal
@davidbombal 2 жыл бұрын
Huge congratulations Patrick! Well done!
@marcorossi2664
@marcorossi2664 10 ай бұрын
Grazie David per i contenuti che divulghi....io sono Italiano e ti seguo da un po...mi hai aperto un mondo....😊
@Denverbi11
@Denverbi11 2 жыл бұрын
Great video. Great Collaboration. I would really enjoy the nmap analysis.
@skriptak6308
@skriptak6308 2 жыл бұрын
I can't tell if that's just David's personality, but I notice he's one of those people that talk over you in a Convo lol ... Chris can't get out a full sentence before David interrupts him ..either way both of these guys are brilliant as well as the video ...love it !
@samjones4327
@samjones4327 2 жыл бұрын
Another awesome video!!! Thank you guys for showing us how to read and interpret the packet capture in wireshark!!! I have a new and easier understanding of what I am looking at! Supurb explanation! Now I have a new toy through GOIP!! I would love to see NMAP in action in wireshark! Thanks David and Chris! Cheers!
@GenXpress
@GenXpress Жыл бұрын
Thank you, David, and in this video Chris too. Your content is great, and I been following you for a while....Keep it up and keep it coming :)
@tmusic99
@tmusic99 Жыл бұрын
Very interesting. I have done a lot of statistical analysis in other domains. Would love to see more statistical analysis examples in Wireshark. And how to export data, filtered or not filtered, to a statistical analysis package.
@dwaynesudduth1028
@dwaynesudduth1028 2 жыл бұрын
Fantastic content once again, proving that you are a top-tier content creator for IT. Thank you and thank you Chris Greer!!
@fritzbiederstadt4869
@fritzbiederstadt4869 7 ай бұрын
I can imagine a lot more utility then just for attacks. Makes me think of EtherPeek IP Maps, the old sniffer pro ip matrix or Skitter application that is or used to be available via CAIDA - pretty cool. Did not know that feature set was available for Wireshark
@majiddehbi9186
@majiddehbi9186 2 жыл бұрын
Such pleasure its real chrismus to have u here guys its so instructive God bless u
@davidbombal
@davidbombal 2 жыл бұрын
Thank you Majid!
@brianturney2124
@brianturney2124 Жыл бұрын
This is great. I love it when you ask lots of questions. I am usually asking the same ones in my head. Perfect!
@kjetilandreedstrm1678
@kjetilandreedstrm1678 2 жыл бұрын
Hi! Great video! I was blown away over this! But it might be just me that is a complete noob. I just find a TCP-handshake file with 15 packets in the WireShark-link above? Should it not be the complete file from the attack Chris is using in the video?
@davidbombal
@davidbombal 2 жыл бұрын
Thanks. Please try this link: davidbombal.wiki/tcphackers1 - looks like I made a mistake :(
@kjetilandreedstrm1678
@kjetilandreedstrm1678 2 жыл бұрын
@@davidbombal Hm. It looks like this link is directing to the same file as the other link??
@zioleo9093
@zioleo9093 2 жыл бұрын
Same File , Just 15 packets.
@itsme7570
@itsme7570 2 жыл бұрын
Sometimes David asks very basic questions but I guess it doesn't hurt
@marcsuhling9317
@marcsuhling9317 2 жыл бұрын
wow this is so interesting to watch and learn from the pros. thanks david for this video.
@naesone2653
@naesone2653 11 ай бұрын
Bunch of questions is great david thank you
@albanselaj733
@albanselaj733 2 жыл бұрын
Thanks, David and Chris! Amazing content that helps us a lot in our everyday work!
@tommyd22277
@tommyd22277 2 жыл бұрын
David this was fantastic! I enjoyed that a lot. Keep bringing the excellent content. I really appreciate you!
@tarrylim778
@tarrylim778 2 жыл бұрын
Excited next video with how nmap scan
@aquadir2830
@aquadir2830 2 жыл бұрын
Thank you so much David.. I'm a big fan of yours.. Happy merry Christmas 🎄..
@batreilangrynjah2526
@batreilangrynjah2526 2 жыл бұрын
thank you David for this I learned a lot ..want some more videos like this
@nallachi2913
@nallachi2913 2 жыл бұрын
Nice conversation both of you chris and DB❤️❤️❤️ are marvelous stuff giving persons
@davidbombal
@davidbombal 2 жыл бұрын
Thank you. Lots of fun talking with Chris about Wireshark 😄
@gamershubke6982
@gamershubke6982 2 жыл бұрын
Love your videos since day one I have learnt alot from you continue doing this great work 💪
@anthonyjohnson2607
@anthonyjohnson2607 2 жыл бұрын
keep on asking questions david, we all have the same questions!
@vyasG
@vyasG 2 жыл бұрын
Thank you David and Chris for this amazing video. Very useful content.
@jointherevolution5577
@jointherevolution5577 2 жыл бұрын
Very good work mate! helped a lot with a uni assignment!
@davidbombal
@davidbombal 2 жыл бұрын
Legit TCP flows or hacking attacks? Can Wireshark help us to decode the flows and see if the traffic is malicious? // WIRESHARK FILE // Download here: www.dropbox.com/s/pvytdvkvxl8b41n/SYNScan_GeoIP_ChrisGreer.pcapng.zip?dl=0 // MAXMIND // How to: wiki.wireshark.org/HowToUseGeoIP Maxmind: www.maxmind.com/en/home // MY STUFF // www.amazon.com/shop/davidbombal // SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal KZbin: kzbin.info //CHRIS GREER // Udemy course: davidbombal.wiki/chriswireshark LinkedIn: www.linkedin.com/in/cgreer/ KZbin: kzbin.info Twitter: twitter.com/packetpioneer // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
@planetbobful
@planetbobful 2 жыл бұрын
Great vid - lekker man! Love the Blue Hat training vids - greatly appreciated!
@davidbombal
@davidbombal 2 жыл бұрын
Happy to hear that :)
@jacobhenriksen2324
@jacobhenriksen2324 2 жыл бұрын
Love these videos! Could watch for hours
@gilbertohernandez9223
@gilbertohernandez9223 2 жыл бұрын
Do you have a podcast by chance? I enjoy hearing you talk about anything computers related.
@joerockhead7246
@joerockhead7246 9 ай бұрын
more Chris. more Chris. more Chris.
@Whit3hat
@Whit3hat 5 ай бұрын
Ask away David, most cases what I was thinking thx
@Andrew-mh6cl
@Andrew-mh6cl 2 жыл бұрын
Congrats sir we ill reach soon 1million best wishes master. ❤️❤️❤️❤️❤️❤️❤️
@davidbombal
@davidbombal 2 жыл бұрын
Thank you!
@avjyots2601
@avjyots2601 2 жыл бұрын
Amazing analysis, thanks 👍
@chris7691
@chris7691 2 жыл бұрын
LOTS OF QUESTIONS
@vikpa1211
@vikpa1211 26 күн бұрын
I think machine learning algorithms can detect those types of patterns and malicious traffic in real time
@glenp42
@glenp42 2 жыл бұрын
Q: Can we get copies of the wireshark profiles used?
@tahersadeghi6773
@tahersadeghi6773 Жыл бұрын
Hey Chris. In this video, you mention a low number in a suspicious 34000 range. Is this number randomly chosen by the server, browser, or person initiating the packet? and what if this number was in the high number range?
@SuperPrabhdeepsingh
@SuperPrabhdeepsingh 2 жыл бұрын
what a video!! Go for nmap for the next video
@ranganathannandakumar4463
@ranganathannandakumar4463 Жыл бұрын
This is GOLD! Thank you!
@juanrodriguez825
@juanrodriguez825 2 жыл бұрын
Nmap
@technoman9926
@technoman9926 2 жыл бұрын
Print ("hello David")
@davidbombal
@davidbombal 2 жыл бұрын
Hello!
@groovetrain397
@groovetrain397 2 жыл бұрын
Ok thats great guys, so how do we block it!??
@fifthamendment1
@fifthamendment1 11 ай бұрын
If the TTL number is close, would it not mean that the source is from the same location? Perhaps the hops were changed up a bit such as sent through various VPNs?
@killerx8902
@killerx8902 2 жыл бұрын
Great stuff and I vote for nmap
@ashersilver7388
@ashersilver7388 2 жыл бұрын
I havnt watched the whole video. But yes, ASK AWAY!!!
@Ak4sh07
@Ak4sh07 2 жыл бұрын
Love You David Bombal
@davidbombal
@davidbombal 2 жыл бұрын
Thank you!
@faran_siddiqui-d3t
@faran_siddiqui-d3t 2 жыл бұрын
David and chris are the best
@davidbombal
@davidbombal 2 жыл бұрын
Thank you!
@scottsparling2591
@scottsparling2591 2 жыл бұрын
so, if UDP is connection-less, but QUIC is happening over UDP, AND has a connection ID and session ID (TLS), are we now to consider UDP in some cases connection oriented, or just consider QUIC connection oriented? I hope my question makes sense to others.
@vivekkrishnan9794
@vivekkrishnan9794 Жыл бұрын
From my understanding, quic is a protocol with connection oriented properties running over udp. UDP itself is not connection oriented
@smokestudio1408
@smokestudio1408 2 жыл бұрын
Really interesting stuff ☺️
@davidbombal
@davidbombal 2 жыл бұрын
Thank you!
@mohamedaymenzebouchi
@mohamedaymenzebouchi 2 жыл бұрын
Yeh, ask questions
@davidbombal
@davidbombal 2 жыл бұрын
Thanks. I'll do that 😄
@Firoz900
@Firoz900 2 жыл бұрын
Great. Thank you guru.
@omkhard1833
@omkhard1833 2 жыл бұрын
Great Video Sir David ....
@davidbombal
@davidbombal 2 жыл бұрын
Glad you liked it!
@RayzDEV
@RayzDEV 2 жыл бұрын
Thanks for video :) very informative.
@davidbombal
@davidbombal 2 жыл бұрын
Glad it was helpful!
@refaiabdeen5943
@refaiabdeen5943 2 жыл бұрын
Cheers Mate.
@mmaranta785
@mmaranta785 Жыл бұрын
Wonderful!
@majiddehbi9186
@majiddehbi9186 2 жыл бұрын
One more question for Chris what's u re idealy profile in whshark in order to get a max of infos when we try to track the wierd packets thx
@davidbombal
@davidbombal 2 жыл бұрын
I'll ask Chris to cover Wireshark profiles in another video 😄
@majiddehbi9186
@majiddehbi9186 2 жыл бұрын
@@davidbombal GOd bless u David and have wonderful Christmas with all u re be loved ones
@Ak4sh07
@Ak4sh07 2 жыл бұрын
Great Content
@davidbombal
@davidbombal 2 жыл бұрын
Thank you!
@fairplay8347
@fairplay8347 2 жыл бұрын
Sir Love from India Iam a CCNP student Should I learn python for future
@symshark
@symshark 2 жыл бұрын
The trace file in the download link only contains the TCP Handshake with 15 packets. Is the trace file used in this video available to download?
@davidbombal
@davidbombal 2 жыл бұрын
Please try again using this link: davidbombal.wiki/tcphackers1 - NOTE please that your browser may cache the incorrect link so you may need to use a private / incognito window or different browser if it doesn't work for you
@ThePumbaadk
@ThePumbaadk 2 жыл бұрын
What a great video, very nice 👍🏻
@davidbombal
@davidbombal 2 жыл бұрын
Thank you very much!
@KevinCrabb
@KevinCrabb 2 жыл бұрын
Hi, David and Chris, I'm having a hard time making it work on my Windows version of Wireshark. I downloaded it for MMDB but it was formatted in tar.gz not .mmdb. So I formatted it to .mmdb, point it to my path folder, restarted Wireshark but no luck. Is there something I'm missing?
@davidbombal
@davidbombal 2 жыл бұрын
There was a problem with the download link. Please try downloading again using the Dropbox link in the video description. It is a zip file that you need to download
@trevorhenrytrey
@trevorhenrytrey 2 жыл бұрын
How do you stop the traffic once you notice this is not normal traffic. Or it's not real time analysis
@mouridmostapha9378
@mouridmostapha9378 2 жыл бұрын
You the best david keep 🔥❤
@danynite9736
@danynite9736 2 жыл бұрын
Hello David I have a problem with Kali Linux in VMBox. When I use firefox, my CPU is 100% overloaded . What can I do against it?
@adolfor5427
@adolfor5427 2 жыл бұрын
Mannnn, this is just cool
@fahadbawazir1771
@fahadbawazir1771 2 жыл бұрын
David sir, I like that..
@davidbombal
@davidbombal 2 жыл бұрын
Really happy to hear that
@ArSiddharth
@ArSiddharth 2 жыл бұрын
I have a question, I'm a beginner, And I do not understand where should I start, from where should I study? I don't understand anything..... Love❤️ from india 🇮🇳
@davidbombal
@davidbombal 2 жыл бұрын
Network+ or CCNA are a great way to start learning basics. Watch this video for more tips: kzbin.info/www/bejne/iXfFh2qpibh0oqM
@ArSiddharth
@ArSiddharth 2 жыл бұрын
@@davidbombal ohh men, thanks a lot, I didn't think you would reply to my comment ,Thanks sir, ♥️♥️
@Thriller627
@Thriller627 2 жыл бұрын
Cheers! P;S. Keep on asking questions.. d ; } #DavidBombal
@yeteldonn4649
@yeteldonn4649 2 жыл бұрын
thx u.
@DevrajSingh-rs7fn
@DevrajSingh-rs7fn 2 жыл бұрын
Hi Big fan of you and your videos
@davidbombal
@davidbombal 2 жыл бұрын
Thank you so much 😀
@abdulrahmanfaisal288
@abdulrahmanfaisal288 2 жыл бұрын
Keep going
@davidbombal
@davidbombal 2 жыл бұрын
Thank you!
@sohilshrestha3089
@sohilshrestha3089 2 жыл бұрын
how to stop my terminal from saving history in kali linux 2021.4
@originals2747
@originals2747 2 жыл бұрын
informative
@davidbombal
@davidbombal 2 жыл бұрын
Glad you enjoyed the video 😄
@jackjohn8323
@jackjohn8323 2 жыл бұрын
Can you share the link to PCAP file please. The one shared only has the Videos but not PCAP
@davidbombal
@davidbombal 2 жыл бұрын
Thanks. I've fixed the link. Please download again. davidbombal.wiki/tcphackers1
@randommiser3310
@randommiser3310 2 жыл бұрын
David from South af
@ArSiddharth
@ArSiddharth 2 жыл бұрын
Sir I'm your Big fan
@davidbombal
@davidbombal 2 жыл бұрын
Thank you!
@ArSiddharth
@ArSiddharth 2 жыл бұрын
Nice video
@davidbombal
@davidbombal 2 жыл бұрын
Thank you very much!
@JarppaGuru
@JarppaGuru 2 жыл бұрын
3:50 now give compare very popular website are they 1 second part.
@SOC_Pavi
@SOC_Pavi 2 жыл бұрын
Hello David, Seems the pcap file that was uploaded to Dropbox only showing 15 packets. I not applied any filters. Could you please check and assist on this.
@davidbombal
@davidbombal 2 жыл бұрын
Please try this link: davidbombal.wiki/tcphackers1
@zioleo9093
@zioleo9093 2 жыл бұрын
@@davidbombal Same 15 Packets only. 😢
@SOC_Pavi
@SOC_Pavi 2 жыл бұрын
@@davidbombalOnly 15 packets in the PCAP file
@sayedislam8117
@sayedislam8117 2 жыл бұрын
Love from 🇧🇩
@davidbombal
@davidbombal 2 жыл бұрын
Thank you and welcome!
@CheeseLayong
@CheeseLayong 2 жыл бұрын
NMAP.
@UrRealestCritic
@UrRealestCritic 2 жыл бұрын
Can I use witeshark on the new M1 MacBook?
@gabethedog4043
@gabethedog4043 2 жыл бұрын
yes
@UrRealestCritic
@UrRealestCritic 2 жыл бұрын
@@gabethedog4043 thanks bro.
@theconfusedhamster
@theconfusedhamster 2 жыл бұрын
Imagine heart and comment from Devid Sir
@davidbombal
@davidbombal 2 жыл бұрын
You got it! Now what?
@theconfusedhamster
@theconfusedhamster 2 жыл бұрын
@@davidbombal now I am Gonna Fall in love for You
@alapanroy1114
@alapanroy1114 Жыл бұрын
I want question ans conversion
@mohamedaymenzebouchi
@mohamedaymenzebouchi 2 жыл бұрын
Yaaah
@davidbombal
@davidbombal 2 жыл бұрын
Hope you enjoy the video!
@mohamedaymenzebouchi
@mohamedaymenzebouchi 2 жыл бұрын
@@davidbombalI did !!!!
@fahadbawazir1771
@fahadbawazir1771 2 жыл бұрын
Good
@davidbombal
@davidbombal 2 жыл бұрын
Thank you Fahad!
@julianllouve4835
@julianllouve4835 2 жыл бұрын
you the best
@tyalva1814
@tyalva1814 2 жыл бұрын
phone verification not working on discord
Wireshark: Packet Analysis and Ethical Hacking Course
5:08
David Bombal
Рет қаралды 52 М.
Disrespect or Respect 💔❤️
00:27
Thiago Productions
Рет қаралды 42 МЛН
Ice Cream or Surprise Trip Around the World?
00:31
Hungry FAM
Рет қаралды 20 МЛН
1, 2, 3, 4, 5, 6, 7, 8, 9 🙈⚽️
00:46
Celine Dept
Рет қаралды 108 МЛН
Decrypting TLS, HTTP/2 and QUIC with Wireshark
28:00
David Bombal
Рет қаралды 108 М.
Simulate TCP Syn Floods with ChatGPT and Wireshark
30:18
Plaintext Packets
Рет қаралды 2,8 М.
How TCP really works: MTU vs MSS
1:07:02
David Bombal
Рет қаралды 156 М.
HTTPS Decryption with Wireshark // Website TLS Decryption
31:14
David Bombal
Рет қаралды 268 М.
Ex-NSA hacker tells us how to get into hacking! (2022 Edition)
50:07
Solving a REAL investigation using OSINT
19:03
Gary Ruddell
Рет қаралды 186 М.
How ARP Poisoning Works // Man-in-the-Middle
13:29
Chris Greer
Рет қаралды 70 М.
She hacked me!
44:13
David Bombal
Рет қаралды 276 М.
😱В Айфоне НЕТ жеста НАЗАД?🤦‍♂️
0:52
Не шарю!
Рет қаралды 72 М.
Это самый популярный гаджет в мире
0:20
Máy báo động cho gia đình mãi đỉnh
0:31
SaboMall
Рет қаралды 32 МЛН