Passive Sniffing Techniques Demo (cyber security)
Budget: $10 – $25 CAD
Objective:
Exemplify Passive sniffing techniques on both your droplet server and localhost machine.
All information does NOT need to come from one droplet and/or one local machine.
Task 1:
Start a packet capture for 2 minutes while browsing a non-sensitive website. A non-sensitive
website is a website where you do not log into.
Apply a filter to show only HTTP or DNS traffic. Submit a screenshot
Identify and extract the source IP, destination IP, and protocol from one captured packet.
Submit a screenshot of the filtered capture with annotations.
Task 2:
Use Wireshark to capture unencrypted traffic on your laptop/desktop localhost network.
Submit a screenshot
Identify a plaintext credential or request (e.g., an HTTP login or an unencrypted message).
Submit a screenshot of that captured data and describe what was exposed
Explain how encryption would prevent this exposure by writing a paragraph-long answer in a .txt file
Task 3:
Navigate to your droplet and block all http traffic to your droplet. Submit the screenshot of the
commands to execute to add and apply the firewall rule.
Open any navigator and confirm that no traffic is being allowed to your droplet. Submit a screenshot
that shows both your IP address and the browser response.
Task 4:
Using the command-line on your local machine’s local host, run the command to show your ARP table.
Submit a screenshot that shows the command and the output of the command.
Using Wireshark, show all ARP traffic of your local machine’s localhost. Submit a screenshot.
Explain how you would mitigate ARP spoofing attacks by writing a paragraph-long answer in a .txt file
Submission Guideline:
• There should be 2 text files and 8 image files, totaling 10 files.
Exemplify Passive sniffing techniques on both your droplet server and localhost machine.
All information does NOT need to come from one droplet and/or one local machine.
Task 1:
Start a packet capture for 2 minutes while browsing a non-sensitive website. A non-sensitive
website is a website where you do not log into.
Apply a filter to show only HTTP or DNS traffic. Submit a screenshot
Identify and extract the source IP, destination IP, and protocol from one captured packet.
Submit a screenshot of the filtered capture with annotations.
Task 2:
Use Wireshark to capture unencrypted traffic on your laptop/desktop localhost network.
Submit a screenshot
Identify a plaintext credential or request (e.g., an HTTP login or an unencrypted message).
Submit a screenshot of that captured data and describe what was exposed
Explain how encryption would prevent this exposure by writing a paragraph-long answer in a .txt file
Task 3:
Navigate to your droplet and block all http traffic to your droplet. Submit the screenshot of the
commands to execute to add and apply the firewall rule.
Open any navigator and confirm that no traffic is being allowed to your droplet. Submit a screenshot
that shows both your IP address and the browser response.
Task 4:
Using the command-line on your local machine’s local host, run the command to show your ARP table.
Submit a screenshot that shows the command and the output of the command.
Using Wireshark, show all ARP traffic of your local machine’s localhost. Submit a screenshot.
Explain how you would mitigate ARP spoofing attacks by writing a paragraph-long answer in a .txt file
Submission Guideline:
• There should be 2 text files and 8 image files, totaling 10 files.