In: Computer Science
You can capture DNS records by executing a nslookup command
You must report which packets represent your DNS query and its DNS response
The easiest way to capture DHCP records in wireshark is to
ipconfig /renew
You must report which packets represent a DHCP query and a DHCP response.
show the steps with the step by step images.
- Kindly upvote
if this helped
Steps to follow:
- Open wireshark
- Add filter - port 53 (for DNS)
- Start capturing
- Hit nslookup for google in command prompt.
- Notice captures packets.
- Using Wifi as my system is connected to wifi (refer image
below)
This DNS activity has been done for google nslookup.
- 1st represents the request
- 4threpresents the reponse for the DNS.
- Other packets provide additional info about the DNS
packets.
1 0.000000 192.168.43.194 192.168.43.1 DNS 85 Standard query 0x0001 PTR 1.43.168.192.in-addr.arpa
2 0.004350 192.168.43.1 192.168.43.194 DNS 85 Standard query response 0x0001 No such name PTR 1.43.168.192.in-addr.arpa
3 0.005915 192.168.43.194 192.168.43.1 DNS 74 Standard query 0x0002 A www.google.com
4 0.751219 192.168.43.1 192.168.43.194 DNS 90 Standard query response 0x0002 A www.google.com A 216.58.197.68
5 0.761750 192.168.43.194 192.168.43.1 DNS 74 Standard query 0x0003 AAAA www.google.com
6 1.405024 192.168.43.1 192.168.43.194 DNS 102 Standard query response 0x0003 AAAA www.google.com AAAA 2404:6800:4002:808::2004
7 10.844031 192.168.43.194 192.168.43.1 DNS 87 Standard query 0x07ef A img-s-msn-com.akamaized.net
8 10.844475 192.168.43.194 192.168.43.1 DNS 87 Standard query 0xd541 AAAA img-s-msn-com.akamaized.net
9 10.981931 192.168.43.1 192.168.43.194 DNS 232 Standard query response 0x07ef A img-s-msn-com.akamaized.net CNAME a1834.dspg2.akamai.net A 23.48.245.201 A 23.48.245.178 A 23.48.245.162 A 23.48.245.171 A 23.48.245.170 A 23.48.245.169 A 23.48.245.179
10 10.981995 192.168.43.1 192.168.43.194 DNS 176 Standard query response 0xd541 AAAA img-s-msn-com.akamaized.net CNAME a1834.dspg2.akamai.net AAAA 2600:140f:e00::1730:f508 AAAA 2600:140f:e00::1730:f511