{"id":239,"date":"2022-01-14T14:09:45","date_gmt":"2022-01-14T14:09:45","guid":{"rendered":"http:\/\/miriamposner.com\/classes\/is270w22\/?page_id=239"},"modified":"2022-01-14T14:19:05","modified_gmt":"2022-01-14T14:19:05","slug":"snoop-on-network-activity-with-wireshark","status":"publish","type":"page","link":"https:\/\/miriamposner.com\/classes\/is270w22\/resources\/snoop-on-network-activity-with-wireshark\/","title":{"rendered":"Snoop on network activity with Wireshark"},"content":{"rendered":"\n<p>Wireshark is a &#8220;packet sniffer,&#8221; meaning it&#8217;s a piece of software that people use to observe and analyze network activity. When Wireshark is \u201ccapturing,\u201d it makes a copy of every packet traveling on your local network and displays it for your examination. It can do pretty sophisticated things &#8212; it&#8217;s actually an industry standard in the field of network analysis &#8212; but we&#8217;ll use it today to peek at network activity, in order to get a better sense of how the internet works.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Download the capture file<\/h3>\n\n\n\n<p>Go to <a href=\"https:\/\/bruinlearn.ucla.edu\/files\/7715424\/download?download_frd=1\">https:\/\/bruinlearn.ucla.edu\/files\/7715424\/download?download_frd=1<\/a> to download our PCAP file. PCAP stands for \u201cpacket capture\u201d and is the standard file format for viewing network activity. Save the file someplace where you&#8217;ll be able to find it easily. You don&#8217;t have to open it quite yet.<\/p>\n\n\n\n<p><em>The picture below is an excerpt from a <a href=\"https:\/\/www.azmirror.com\/blog\/inspired-by-mike-lindell-republicans-demand-information-from-elections-officials\/)\">newspaper article<\/a> about Republican attempts to prove that voter fraud took place over networks. You can see that PCAPs are the standard way network experts analyze network activity.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"447\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/download-the-capture-file-1024x447.png\" alt=\"\" class=\"wp-image-240\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/download-the-capture-file-1024x447.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/download-the-capture-file-300x131.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/download-the-capture-file-768x336.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/download-the-capture-file-228x100.png 228w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/download-the-capture-file.png 1460w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">2. Open Wireshark<\/h3>\n\n\n\n<p>Double-click on Wireshark to open it. You&#8217;re greeted with a welcome screen.<\/p>\n\n\n\n<p>(Note: If Wireshark starts capturing as soon as you open it &#8212; you can tell because the main window will immediately fill with lines of text &#8212; press the stop sign next to the shark fin at the top left of the Wireshark window. Then continue.)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"479\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-wireshark-1024x479.png\" alt=\"\" class=\"wp-image-241\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-wireshark-1024x479.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-wireshark-300x140.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-wireshark-768x359.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-wireshark-1536x718.png 1536w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-wireshark-2048x957.png 2048w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-wireshark-1568x733.png 1568w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-wireshark-228x107.png 228w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">3. Open the sample PCAP file.<\/h3>\n\n\n\n<p>Click on <strong>File<\/strong>, then <strong>Open<\/strong>, and then find the file you downloaded in step 1.<\/p>\n\n\n\n<p>(If you had to press the stop sign in the previous step, Wireshark may ask you if you want to &#8220;save the current capture.&#8221; You don&#8217;t. Press &#8220;continue without saving.&#8221;)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"483\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-the-sample-pcap-file-1024x483.png\" alt=\"\" class=\"wp-image-242\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-the-sample-pcap-file-1024x483.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-the-sample-pcap-file-300x141.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-the-sample-pcap-file-768x362.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-the-sample-pcap-file-1536x724.png 1536w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-the-sample-pcap-file-1568x739.png 1568w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-the-sample-pcap-file-228x107.png 228w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/open-the-sample-pcap-file.png 1714w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">4. What are you looking at?<\/h3>\n\n\n\n<p>Wireshark&#8217;s interface consists of three main panes. The first, the main window, contains a list of all the network activity Wireshark observed during the capture period. (The colors of the highlighting on your version might be different from mine.) <a href=\"https:\/\/www.wireshark.org\/docs\/wsug_html_chunked\/ChCustColorizationSection.html\">What are the color codes?<\/a> The second, the middle window, gives you information about the highlighted line. The third, bottom window contains the actual message, in bytes. Usually it&#8217;s hard to read because it&#8217;s in hexadecimal and then ASCII code. You can minimize that bottom window, if you want.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"487\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/what-are-you-looking-at--1024x487.png\" alt=\"\" class=\"wp-image-243\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/what-are-you-looking-at--1024x487.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/what-are-you-looking-at--300x143.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/what-are-you-looking-at--768x365.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/what-are-you-looking-at--228x108.png 228w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/what-are-you-looking-at-.png 1498w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">5. Anatomy of a packet<\/h3>\n\n\n\n<p>The number column <strong>(1) <\/strong>tells you which line you&#8217;re on in your list of packets. That also serves as a good way to identify which packet you&#8217;re talking about. The Time column <strong>(2)<\/strong> tells you how many seconds have elapsed since the capture started. Source <strong>(3)<\/strong> is the network address (IP address) from which the packet was generated. Destination <strong>(4)<\/strong> is the IP address to which the packet was sent. Protocol <strong>(5)<\/strong>, of course, tells you which protocol was contained in the packet. Length <strong>(6)<\/strong> tells you how many characters the packet contains. And Info<strong> (7)<\/strong> gives you more information about the request.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"269\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/anatomy-of-a-packet-1024x269.png\" alt=\"\" class=\"wp-image-244\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/anatomy-of-a-packet-1024x269.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/anatomy-of-a-packet-300x79.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/anatomy-of-a-packet-768x202.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/anatomy-of-a-packet-228x60.png 228w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/anatomy-of-a-packet.png 1286w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">6. Get some information about the PCAP<\/h3>\n\n\n\n<p>There are so many lines here, it&#8217;s hard to tell what&#8217;s going on. Let&#8217;s try to get an overview of the entire capture. From the <strong>Statistics <\/strong>menu at the top of your screen, choose <strong>Capture File Properties<\/strong>. In the ensuing window, you can get some useful information about the PCAP: for example, it captures 12 seconds of activity and 1,961 packets. (You can also tell what kind of computer I have!)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"703\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/get-some-information-about-the-pcap-1024x703.png\" alt=\"\" class=\"wp-image-250\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/get-some-information-about-the-pcap-1024x703.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/get-some-information-about-the-pcap-300x206.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/get-some-information-about-the-pcap-768x528.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/get-some-information-about-the-pcap-169x116.png 169w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/get-some-information-about-the-pcap.png 1348w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">7. Snoop on my web activity<\/h3>\n\n\n\n<p>In the 12 seconds that elapsed, I visited some websites. Remember, every time I typed a URL in my browser, my browser sent out a DNS request, in order to translate that URL into a website address. So let&#8217;s just look at DNS requests. In the <strong>Display filter<\/strong> window above the main pane, type <strong>dns<\/strong>. The search box will turn green when you&#8217;ve entered a kind of protocol that Wireshark understands; you can&#8217;t just enter anything! Press enter.<\/p>\n\n\n\n<p>Now you&#8217;ll see only DNS requests.<\/p>\n\n\n\n<p><strong>Question 1: Can you tell what my favorite hobby is? <\/strong>(Hint: look carefully at the Info column.)<\/p>\n\n\n\n<p><strong>Question 2: I only entered two URLs during the capture period.<\/strong> <strong>Why do you think there are so many DNS requests during this period?<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"461\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/snoop-on-my-web-activity-1024x461.png\" alt=\"\" class=\"wp-image-245\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/snoop-on-my-web-activity-1024x461.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/snoop-on-my-web-activity-300x135.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/snoop-on-my-web-activity-768x346.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/snoop-on-my-web-activity-1536x691.png 1536w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/snoop-on-my-web-activity-1568x706.png 1568w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/snoop-on-my-web-activity-228x103.png 228w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/snoop-on-my-web-activity.png 1578w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">8. Make the addresses a little easier to read.<\/h3>\n\n\n\n<p>Delete the dns filter from the <strong>Display filter <\/strong>window by clicking on the tiny <strong>x<\/strong> at the far right of the search bar. You should now see all the packets again.It might make your work a little easier if you convert the IP addresses into human-readable names. From the <strong>View <\/strong>menu, choose <strong>Name resolution<\/strong> and check <strong>Resolve network addresses.<\/strong> Wireshark won&#8217;t be able to resolve every address (<a href=\"https:\/\/documentation.help\/Wireshark\/ChAdvNameResolutionSection.html\">why not<\/a>?) but it will make some IP addresses easier to read.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"646\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/make-the-addresses-a-little-easier-to-read-1024x646.png\" alt=\"\" class=\"wp-image-246\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/make-the-addresses-a-little-easier-to-read-1024x646.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/make-the-addresses-a-little-easier-to-read-300x189.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/make-the-addresses-a-little-easier-to-read-768x485.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/make-the-addresses-a-little-easier-to-read-184x116.png 184w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/make-the-addresses-a-little-easier-to-read.png 1382w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">9. See the protocol breakdown<\/h3>\n\n\n\n<p>Let&#8217;s look at the percentage breakdown of the various protocols. From the <strong>Statistics<\/strong> menu, select <strong>Protocol Hierarchy<\/strong>. This tells you what percentage of packets contain each kind of protocol. Why do the numbers add up to more than 100%? That&#8217;s because each packet actually contains multiple protocols, even though Wireshark has divided them up in the main window so that you can focus on each protocol, one at a time.<\/p>\n\n\n\n<p><strong>Question 3: Most packets contain either TCP or UDP protocols. Why would that be?<\/strong><\/p>\n\n\n\n<p><strong>Question 4: What&#8217;s the Address Resolution Protocol? What&#8217;s it doing there?<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"847\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/see-the-protocol-breakdown-1024x847.png\" alt=\"\" class=\"wp-image-247\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/see-the-protocol-breakdown-1024x847.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/see-the-protocol-breakdown-300x248.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/see-the-protocol-breakdown-768x635.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/see-the-protocol-breakdown-140x116.png 140w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/see-the-protocol-breakdown.png 1194w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">10. Investigate a packet<\/h3>\n\n\n\n<p>Scroll down to line 1750. It looks a little different from the others.<\/p>\n\n\n\n<p><strong>Question 5: Can you tell what&#8217;s going on in here? <\/strong>(Feel free to Google terms.)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"491\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/investigate-a-request-1024x491.png\" alt=\"\" class=\"wp-image-252\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/investigate-a-request-1024x491.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/investigate-a-request-300x144.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/investigate-a-request-768x368.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/investigate-a-request-228x109.png 228w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/investigate-a-request.png 1340w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">11. Background noise<\/h3>\n\n\n\n<p>If your computer is connected to the internet, it&#8217;s always chattering away, even if you&#8217;re not doing anything.<\/p>\n\n\n\n<p><strong>Question 6: Can you tell what service I use to sync my files to the cloud? <\/strong>(Hint: Start from the first line and scroll down slowly. You should be able to figure this out by the time you get to line 300.)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"381\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/background-noise-1024x381.png\" alt=\"\" class=\"wp-image-248\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/background-noise-1024x381.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/background-noise-300x112.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/background-noise-768x286.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/background-noise-1536x572.png 1536w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/background-noise-2048x762.png 2048w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/background-noise-1568x584.png 1568w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/background-noise-228x85.png 228w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">12. Capture your own activity<\/h3>\n\n\n\n<p>WARNING: this file will get big FAST, especially since you&#8217;re running Zoom, so start and stop the capture within a few seconds!<\/p>\n\n\n\n<p>OK, want to see what someone could see if they sniffed packets on your network? It&#8217;s easy to capture packets!<\/p>\n\n\n\n<p>Click on the blue sharkfin at the top left of the Wireshark interface.<\/p>\n\n\n\n<p><em>You may be presented with a screen like that pictured in step 2, in which you are asked to choose between various kinds of network connections, like Wi-Fi, ethernet, and a bunch of uninterpretable names. You probably want wifi &#8212; pick the connection that has the most activity, as shown in its corresponding line graph.<\/em><\/p>\n\n\n\n<p>Then VERY QUICKLY click on the stop sign right next door to the shark fin. By default Wireshark&#8217;s captures are &#8220;promiscuous,&#8221; meaning they capture not only your own activity but the activity of every device on the same network as you.<\/p>\n\n\n\n<p><strong>Question 7: What do you see? What could someone tell about you and your household from a few seconds of your network activity?<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"775\" src=\"http:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/capture-your-own-activity-1024x775.png\" alt=\"\" class=\"wp-image-253\" srcset=\"https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/capture-your-own-activity-1024x775.png 1024w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/capture-your-own-activity-300x227.png 300w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/capture-your-own-activity-768x581.png 768w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/capture-your-own-activity-153x116.png 153w, https:\/\/miriamposner.com\/classes\/is270w22\/wp-content\/uploads\/sites\/19\/2022\/01\/capture-your-own-activity.png 1406w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Wireshark is a &#8220;packet sniffer,&#8221; meaning it&#8217;s a piece of software that people use to observe and analyze network activity. When Wireshark is \u201ccapturing,\u201d it makes a copy of every&hellip; <a class=\"more-link\" href=\"https:\/\/miriamposner.com\/classes\/is270w22\/resources\/snoop-on-network-activity-with-wireshark\/\">Continue reading <span class=\"screen-reader-text\">Snoop on network activity with Wireshark<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":75,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_eb_attr":"","footnotes":""},"class_list":["post-239","page","type-page","status-publish","hentry","entry"],"_links":{"self":[{"href":"https:\/\/miriamposner.com\/classes\/is270w22\/wp-json\/wp\/v2\/pages\/239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/miriamposner.com\/classes\/is270w22\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/miriamposner.com\/classes\/is270w22\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/miriamposner.com\/classes\/is270w22\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/miriamposner.com\/classes\/is270w22\/wp-json\/wp\/v2\/comments?post=239"}],"version-history":[{"count":0,"href":"https:\/\/miriamposner.com\/classes\/is270w22\/wp-json\/wp\/v2\/pages\/239\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/miriamposner.com\/classes\/is270w22\/wp-json\/wp\/v2\/pages\/75"}],"wp:attachment":[{"href":"https:\/\/miriamposner.com\/classes\/is270w22\/wp-json\/wp\/v2\/media?parent=239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}