Getting Started in Packet Decoding w/ Chris Brenton Day Two!
Day two was a lot more complex than day one. In addition, since this week is packed with the start of summer, graduations, and general kid stuff, I was unable to watch the whole thing. I’ll have to catch the recording later.
We started with IP ID’s and IP Flags and then moved fragmentation. I was able to follow a long, but it’s going to take more study to really grasp it.
Then things got super interesting with TTL and how traceroute works. I love learning all these cool tricks, like how to spot firewalls based on hops and TTL, as well as fingerprinting systems based on the TTL. Meanwhile Chris is tieing everything back to the packet and IP header and what fields are responsible for what. We covered spoofing and more.

Then we dove into IP Options and Source Routing. This was new territory for me. It was mind bending. It’s super helpful that Chris walks through an example, then has us do another one on our own. For these labs we were loading pcap files into Wireshark and on the CLI using tshark. We also learned to do a blind/idle port scan, which is so cool!
We learned how to use wireshark and Hex decode of LSRR packet. I had not yet used the HEX part of Wireshark, so this was all new as well.
Things started getting deeper with decrypting some real world hacking in a pcap file. Looking at ICMP we discovered Command & Control going on by looking at echo responses not returning identical payloads. They were in fact a reverse shell and the command being run on the compromised system.
I really enjoy the way Chris leads the class and the funny and interesting banter throughout the class on Discord.
A few random things I picked up today:
- Analyzing a Log4j Exploit with Wireshark (and how to filter for it) // Sample PCAP!
- Malware of the Day
- Malware Analysis
P
Days III and IV coming soon!
