Práctica de Análisis de Captura de Datos
5. Análisis trama d
00 0b 6a 39 7e 79 00 a0 24 a0 4f ad 08 00 45 00
00 6f 00 00 40 00 40 11 e0 59 a3 0a 0a 02 a3 0a
0a 0e 00 35 04 36 00 5b 91 24 00 b7 81 80 00 01
00 01 00 02 00 00 03 77 77 77 05 63 69 73 63 6f
03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00
01 51 80 00 04 c6 85 db 19 c0 10 00 02 00 01 00
01 51 80 00 06 03 6e 73 31 c0 10 c0 10 00 02 00
01 00 01 51 80 00 06 03 6e 73 32 c0 10
Header del Frame
00 0b 6a 39 7e 79> 6 Bytes MAC de Destino
00 a0 24 a0 4f ad > 6 Bytes , Mac de Origen
08 00 > Tipo Datagrama IP
Header del Datagrama IP
45 >Versi ón (0100 ) y long. del Header en palabras de 32 bits (01010 =5) , 00 > TOS
00 6f > Largo en Bytes 111. (20 Header IP+ 8 Header UDP+83 =>OK)
00 00 > ID 0
40 00 > > 010= Flag DF=1,MF=0 , 0 0000 0000 0000(13)= Offset
40 >TTL , 11> Protocol UDP
e0 59 >Header Checksum,
a3 0a 0a 02 >IP Source 163.10.10.2
a3 0a 0a 0e > IP Dest. 163.10.10.1
Header de UDP ( 8 bytes)
00 35 Source Port Number 53 (DNS)
04 36 Dest. Port Number 1078
00 5b UDP Length 91 bytes ( datos 83+ Header 8 => ok)
91 24 UDP CRC
Datos de UPD del DNS ( total 83 bytes)
00 b7 81 80 00 01 00 01 00 02 00 00 DNS >Header 12 Bytes
03 77 77 77 05 63 69 73 63 6f 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 > Question 25 bytes
00 01 51 80 00 04 c6 85 db 19 c0 10 00 02 00 01> IP Address 16 bytes de cisco 198.133.219.25
00 01 51 80 00 06 03 6e 73 31 c0 10 c0 10 00 02 IP Address 16 bytes
00 01 00 01 51 80 00 06 03 6e 73 32 c0 10
Conclusión de trama c : el Host 163.10.10.2 responde la consulta DNS sobre la IP de www.cisco.com
que es : c6 85 db 19 =198.133.219.25