Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Watch Your Own Browser's DNS (UDP) and HTTPS (TCP) Traffic in Wireshark and Label Each Layer

Beginner40 minWireshark (free) · Any web browser

Course: Cyber Security · Chapter 3: OSI Model, TCP/IP Model, TCP vs UDP and the 3-Way Handshake

Chapter 3 explains the OSI model, TCP vs UDP and the 3-way handshake; this lab shows them in real packets.

Chala mitrano! The OSI model looks like theory until you see a real packet. Today we capture our own laptop's traffic for one minute and find two things: a DNS question (UDP) and a TCP handshake for an HTTPS website. Only our own traffic, on our own laptop. Mag OSI kadhi visrnar nahi!

Suppose we are…

Suppose we are a network trainee at Airtel. A customer says "Google opens slowly". Before blaming the line, a network engineer looks at the packets: did the DNS answer come quickly, and did the TCP connection start cleanly? Wireshark (a free program that shows every packet going in and out of a network card) lets us see exactly that. We practise on our own laptop.

Goal of this lab

By the end you will have:

  • A short capture of your own laptop's traffic.
  • One DNS query and its answer, and you can say why DNS uses UDP (fast, no connection set-up).
  • One TCP 3-way handshake (SYN, SYN-ACK, ACK) to port 443, and the OSI layers of one packet labelled.

What you need (all free)

  • Your own laptop (Windows, Mac or Linux).
  • Wireshark from https://www.wireshark.org/download.html. On Windows, let the installer also install Npcap (the driver that lets Wireshark read packets).
  • 35–40 minutes.

Safety and ethics

Capture only your own laptop's traffic on your own network. Capturing other people's traffic on an office, college or café network without written permission is not allowed and can be a crime. Delete the capture file when you finish, because it can contain the names of sites you visited.

Steps

  1. Install and open Wireshark. On the start screen you see a list of network interfaces with small live graphs.
  2. Double-click the interface that shows activity: Wi-Fi on Windows, Wi-Fi: en0 on a Mac.

    What you should see: packets scrolling in rows, with columns No., Time, Source, Destination, Protocol, Length, Info.

  3. Open your browser and visit https://www.wikipedia.org. Wait 5 seconds.

  4. Click the red square Stop button in Wireshark.
  5. In the display filter bar at the top (it says "Apply a display filter"), type dns and press Enter.

    What you should see: pairs of rows such as Standard query 0x1a2b A www.wikipedia.org and Standard query response 0x1a2b A www.wikipedia.org A 103.102.166.224.

  6. Click a query row. In the middle pane, see the layers from top to bottom: Frame, Ethernet II, Internet Protocol Version 4, User Datagram Protocol (Src Port something, Dst Port 53), Domain Name System.

  7. Write down the IP address in the response. That is where the browser will connect.
  8. Change the filter to the following (replace the address with the one you wrote down) and press Enter:

    ip.addr == 103.102.166.224 && tcp.port == 443
    
  9. Find the first three rows. Their Info column shows [SYN], [SYN, ACK] and [ACK].

    What you should see: the 3-way handshake: your laptop asks (SYN), the server agrees (SYN, ACK), your laptop confirms (ACK). Right after it comes Client Hello (TLS, the start of HTTPS encryption).

  10. Click the Client Hello row. Expand Transport Layer Security → Handshake Protocol: Client Hello → Extension: server_name. You will see www.wikipedia.org; the page content after this is encrypted.

  11. On paper, label one packet with OSI layers: Layer 2 = Ethernet II (MAC addresses), Layer 3 = IPv4 (IP addresses), Layer 4 = TCP or UDP (ports), Layer 7 = DNS or TLS/HTTPS.
  12. Close Wireshark and click Quit without Saving, or delete the saved file.

Ravindra Bagale's Tip

Beginners type dns in the capture filter box on the start page instead of the display filter bar, and then nothing is captured. Start the capture with no filter, then filter what you see. Ani ho, Wireshark madhe 1 minute capture puresa aahe.

Common mistakes

Mistake What happens Fix
Choosing a quiet interface (for example Ethernet when you use Wi-Fi) No packets appear Pick the interface whose small graph is moving
Npcap not installed on Windows "No interfaces found" Re-run the Wireshark installer and tick Install Npcap
Browser already has the site's IP cached No DNS query for that site Visit a site you have not opened today, or run ipconfig /​flushdns (Windows) first
Expecting to read the HTTPS page text You only see "Application Data" That is encryption working; only DNS and the TLS server name are visible
Capturing for many minutes Thousands of rows and a big file Capture 30–60 seconds only

Self-check checklist

0 of 6 done

Try-at-home challenge

Filter with tcp.flags.syn == 1 && tcp.flags.ack == 0. This shows only the first packet (SYN) of every new TCP connection. Open one news website and count how many new connections it makes. Why does one page need so many?

Check your answer

A news page loads pictures, fonts, ads and scripts from many different servers (content delivery networks, ad and analytics servers). Each server needs its own DNS lookup and its own TCP handshake, so 20–60 SYN packets for one page is normal.

Samjla ka? DNS asks over UDP, HTTPS talks over TCP, and every packet carries all the layers. Aata pudhe jaauya: Chapter 4 builds our own server on AWS.