Labs · Cyber Security
Lab: Watch Your Own Browser's DNS (UDP) and HTTPS (TCP) Traffic in Wireshark and Label Each Layer
Course: Cyber Security · Chapter 3: OSI Model, TCP/IP Model, TCP vs UDP and the 3-Way Handshake
Chapter 3 explains the OSI model, TCP vs UDP and the 3-way handshake; this lab shows them in real packets.
Chala mitrano! The OSI model looks like theory until you see a real packet. Today we capture our own laptop's traffic for one minute and find two things: a DNS question (UDP) and a TCP handshake for an HTTPS website. Only our own traffic, on our own laptop. Mag OSI kadhi visrnar nahi!
चला मित्रांनो! खरा packet बघेपर्यंत OSI model फक्त theory वाटतं. आज आपण आपल्या laptop चं traffic एक मिनिट capture करणार आणि दोन गोष्टी शोधणार: एक DNS प्रश्न (UDP) आणि HTTPS website साठी TCP handshake. फक्त आपलं traffic, आपल्याच laptop वर. मग OSI कधी विसरणार नाही!
चलो दोस्तों! जब तक असली packet न देखो, OSI model सिर्फ theory लगता है। आज हम अपने laptop का traffic एक मिनट capture करेंगे और दो चीज़ें ढूँढेंगे: एक DNS सवाल (UDP) और HTTPS website के लिए TCP handshake। सिर्फ अपना traffic, अपने ही laptop पर। फिर OSI कभी नहीं भूलोगे!
Suppose we are…
Suppose we are a network trainee at Airtel. A customer says "Google opens slowly". Before blaming the line, a network engineer looks at the packets: did the DNS answer come quickly, and did the TCP connection start cleanly? Wireshark (a free program that shows every packet going in and out of a network card) lets us see exactly that. We practise on our own laptop.
Goal of this lab
By the end you will have:
- A short capture of your own laptop's traffic.
- One DNS query and its answer, and you can say why DNS uses UDP (fast, no connection set-up).
- One TCP 3-way handshake (SYN, SYN-ACK, ACK) to port 443, and the OSI layers of one packet labelled.
What you need (all free)
- Your own laptop (Windows, Mac or Linux).
- Wireshark from
https://www.wireshark.org/download.html. On Windows, let the installer also install Npcap (the driver that lets Wireshark read packets). - 35–40 minutes.
Safety and ethics
Capture only your own laptop's traffic on your own network. Capturing other people's traffic on an office, college or café network without written permission is not allowed and can be a crime. Delete the capture file when you finish, because it can contain the names of sites you visited.
Steps
- Install and open Wireshark. On the start screen you see a list of network interfaces with small live graphs.
-
Double-click the interface that shows activity: Wi-Fi on Windows, Wi-Fi: en0 on a Mac.
What you should see: packets scrolling in rows, with columns No., Time, Source, Destination, Protocol, Length, Info.
-
Open your browser and visit
https://www.wikipedia.org. Wait 5 seconds. - Click the red square Stop button in Wireshark.
-
In the display filter bar at the top (it says "Apply a display filter"), type
dnsand press Enter.What you should see: pairs of rows such as
Standard query 0x1a2b A www.wikipedia.organdStandard query response 0x1a2b A www.wikipedia.org A 103.102.166.224. -
Click a query row. In the middle pane, see the layers from top to bottom: Frame, Ethernet II, Internet Protocol Version 4, User Datagram Protocol (Src Port something, Dst Port 53), Domain Name System.
- Write down the IP address in the response. That is where the browser will connect.
-
Change the filter to the following (replace the address with the one you wrote down) and press Enter:
ip.addr == 103.102.166.224 && tcp.port == 443 -
Find the first three rows. Their Info column shows [SYN], [SYN, ACK] and [ACK].
What you should see: the 3-way handshake: your laptop asks (SYN), the server agrees (SYN, ACK), your laptop confirms (ACK). Right after it comes Client Hello (TLS, the start of HTTPS encryption).
-
Click the Client Hello row. Expand Transport Layer Security → Handshake Protocol: Client Hello → Extension: server_name. You will see
www.wikipedia.org; the page content after this is encrypted. - On paper, label one packet with OSI layers: Layer 2 = Ethernet II (MAC addresses), Layer 3 = IPv4 (IP addresses), Layer 4 = TCP or UDP (ports), Layer 7 = DNS or TLS/HTTPS.
- Close Wireshark and click Quit without Saving, or delete the saved file.
Ravindra Bagale's Tip
Beginners type dns in the capture filter box on the start page instead of the display filter bar, and then nothing is captured. Start the capture with no filter, then filter what you see. Ani ho, Wireshark madhe 1 minute capture puresa aahe.
Ravindra Bagale's Tip – मराठी
Beginners start page वरच्या capture filter box मध्ये dns टाकतात, display filter bar मध्ये नाही, आणि मग काहीच capture होत नाही. आधी filter शिवाय capture सुरू करा, मग जे दिसतंय त्यावर filter लावा. आणि हो, Wireshark मध्ये 1 minute capture पुरेसा आहे.
Ravindra Bagale's Tip – हिंदी
Beginners start page के capture filter box में dns डाल देते हैं, display filter bar में नहीं, और फिर कुछ capture नहीं होता। पहले बिना filter के capture शुरू करो, फिर जो दिख रहा है उस पर filter लगाओ। और हाँ, Wireshark में 1 minute का capture काफी है।
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Choosing a quiet interface (for example Ethernet when you use Wi-Fi) | No packets appear | Pick the interface whose small graph is moving |
| Npcap not installed on Windows | "No interfaces found" | Re-run the Wireshark installer and tick Install Npcap |
| Browser already has the site's IP cached | No DNS query for that site | Visit a site you have not opened today, or run ipconfig /flushdns (Windows) first |
| Expecting to read the HTTPS page text | You only see "Application Data" | That is encryption working; only DNS and the TLS server name are visible |
| Capturing for many minutes | Thousands of rows and a big file | Capture 30–60 seconds only |
Self-check checklist
0 of 6 done
Try-at-home challenge
Filter with tcp.flags.syn == 1 && tcp.flags.ack == 0. This shows only the first packet (SYN) of every new TCP connection. Open one news website and count how many new connections it makes. Why does one page need so many?
Check your answer
A news page loads pictures, fonts, ads and scripts from many different servers (content delivery networks, ad and analytics servers). Each server needs its own DNS lookup and its own TCP handshake, so 20–60 SYN packets for one page is normal.
Samjla ka? DNS asks over UDP, HTTPS talks over TCP, and every packet carries all the layers. Aata pudhe jaauya: Chapter 4 builds our own server on AWS.