5 Comments

  1. Some other questions? Where were they to meet? Who did Ann love. The answers are in there as well, you need something other than pcaps to find it though. Nothing complhex. Eventually you will say ahh, ascii,

  2. What’s up with frames # 15 and #16 being out of sequence? 15 is clearly the ACK to 16 (acking # 13), based both on sequence and TCP timestamp opt header, but the packet order capture is off. Is this an artifact of capturing on a switched network – frames buffered before forwarding on the receive port – or is it something more sinister?

    I especially like the AIM client on Sec558user’s PC downloading the advert starting in frame 227 – nice touch of realism.

  3. @shewfig:

    It’s an unfortunate fact of life for us: packets don’t always flow by our sensors in the order in which they were sent — or even the order in which they were received by their endpoints! 🙁

    In this case you’re probably right: buffering on a “switched network” (actually a VMware virtual network) caused them to show up out of order. But understand that this happens all the time across the long haul. Latencies vary by path, and packets get to have their very own paths sometimes, hence the whole point of packet-switched networks.

    Thank goodness we don’t often have to reassemble them manually. 🙂

    /jonathan

  4. Shewfig “I especially like the AIM client on Sec558user’s PC downloading the advert starting in frame 227 – nice touch of realism”
    Could you post that for me? I missed that I think.
    Richard

  5. Is there a location to view the solutions to the question after the winner has been announced ? I will really like to know if anyone is willing to share their solution. I am pretty new to the network forensic in general.

    Thanks !

    Israel.

Leave a Reply

Your email address will not be published.

*