This is a preview. You must login to view/edit this pcap.

O 1. 00000001.000000000001 » 00000000.ffffffffffff browser Host Announcement LAZARUS, Workstation, Server, NT Workstation, Potential Browser
O 2. 00:11:95:c2:e7:8a » ff:ff:ff:ff:ff:ff llc U, func=UI; SNAP, OUI 0x000000 (Encapsulated Ethernet), PID 0x5000
O 3. 10.0.0.100 » 239.255.255.250 ssdp M-SEARCH * HTTP/1.1
O 4. 00:11:95:c2:e7:8a » ff:ff:ff:ff:ff:ff llc U, func=UI; SNAP, OUI 0x000000 (Encapsulated Ethernet), PID 0xD900
O 5. 10.0.0.100 » 10.0.0.222 tcp 1078 > 80 [SYN] Seq=0 Win=64512 Len=0 MSS=1460

Here are some of things that registered users can do with this pcap:

  • Reorder packets
  • Fragment packets
  • Reassemble TCP streams
  • Rewrite TCP streams (over IPv4 and IPv6)
  • Extract embedded HTTP content
  • Convert any packet into a DoS generator