Analyze ARP Poisoning with Wireshark
You are the security analyst for a small corporate network. You believe that a hacker has penetrated your network and is using ARP poisoning to infiltrate it.
In this lab, your task is to determine whether ARP poisoning is taking place by doing the following:
- Use Wireshark to capture packets on the enp2s0 interface for five seconds.
- Analyze the Wireshark packets to determine whether ARP poisoning is taking place.
- Use the 192.168.0.2 IP address to help make your determination.
- Answer the questions.
EXPLANATION
Complete this lab as follows:
- Using Wireshark, capture packets for a short time.
- From the Favorites bar, select Wireshark.
- Maximize the window for easier viewing.
- Under Capture, select enp2s0.
- Select the blue fin to start a Wireshark capture.
- After capturing packets for five seconds, select the red box to stop the Wireshark capture.
- Filter for ARP packets and answer the question.
- In the Apply a display filter field, type arp and press Enter to only show ARP packets.
- In the Info column, look for the lines containing the 192.168.0.2 IP address.
- In the top right, select Answer Questions.
- Answer the questions.
- Select Score Lab.
Comments
Post a Comment