TryHackMe WIRESHARK Filters Walkthrough

Поделиться
HTML-код
  • Опубликовано: 2 июн 2024
  • In this video we walkthrough the Wireshark Filters room on TryHackMe. We will look at each filter that we need to build in order to answer the questions, and examine some options for each one.
    TryHackMe Room Link: www.tryhackme.com/jr/wiresharkfilters
    Register for a free account and let's dig!
    == More On-Demand Training from Chris ==
    ▶Getting Started with Wireshark - bit.ly/udemywireshark
    ▶Getting Started with Nmap - bit.ly/udemynmap
    == Live Wireshark Training ==
    ▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
    == Private Wireshark Training ==
    Let's get in touch - packetpioneer.com/product/pri...
    0:00 Intro
    1:51 Task 2 - Protocol Filters
    7:01 Task 3 - IP Filters
    12:10 Task 4 - TCP Filters
    18:53 Task 5 - DNS Filters
    25:38 Task 6 - Special Operators
    30:15 Task 7 - Putting It Together: Filtering for Scans
    37:02 Filtering For Usernames/Passwords
    43:17 Conclusion
  • НаукаНаука

Комментарии • 67

  • @_JohnHammond
    @_JohnHammond Год назад +28

    YEEEEEAAAAAAAAAAHHHHHHHH

    • @adamn777
      @adamn777 Год назад +2

      What about Mr. Hammond? Will we be seeing a THM room by you soon?

  • @majiddehbi9186
    @majiddehbi9186 Год назад +2

    woow so clairly explained chris you are the magicien of the packets thx and God bless u for all what u are given

  • @dandele123
    @dandele123 Год назад +1

    Your videos are phenomenal!

  • @yoshi8171
    @yoshi8171 2 месяца назад

    Great contents!
    This one still doesn't show up in the search result in THM, though the other Wireshark related rooms do.
    It's a pity many people cannot find this in search, thus cannot reach out.
    Huge thanks to Chris from Tokyo 🙏

  • @adamn777
    @adamn777 Год назад +1

    Love the extra insight given on this video. Love it.

  • @135qwerthi
    @135qwerthi Год назад +1

    Oh boy! Cant wait to get my hands on this one!!!
    Thanks for this Chris

    • @ChrisGreer
      @ChrisGreer  Год назад +1

      Report back and let us know what you think!

  • @dwaynesudduth1028
    @dwaynesudduth1028 Год назад

    I just finished this earlier (started this morning then had some things to do and came back to it). two words: LOVED IT. Specifically: I loved how you put in questions that were not explicitly covered in the reading material attached to each task. Instead, some questions made you go out and figure out what you were specifically wanting for an answer.
    Awesome job!!

    • @ChrisGreer
      @ChrisGreer  Год назад +1

      Nice job Dwayne! Glad you liked the wireshark room. Thanks for the comment.

    • @dwaynesudduth1028
      @dwaynesudduth1028 Год назад +1

      @@ChrisGreer Indeed---learned a few new tricks for my 'bag'. Thanks again for all the effort you put out for us!

  • @themonkeysteeze
    @themonkeysteeze Год назад

    need more of these wire shark walkthrough's!

    • @ChrisGreer
      @ChrisGreer  Год назад +2

      More on the way! There is a long Wireshark room on THM that I am shooting now.

  • @andrewrx88
    @andrewrx88 Год назад

    Thanks for the update!

  • @jjames7206
    @jjames7206 Год назад

    It is Great ! Chris, I got the feeling when I working on it. Thanks bro

  • @mahfoudtoubalseghir3673
    @mahfoudtoubalseghir3673 Год назад

    awesome room!
    just completed it and the reason I could do so is thanks to your course on Udemy. It helped a lot!

  • @MikeBramm
    @MikeBramm Год назад

    Thanks Chris. I always pick up a few new tricks from watching your videos.

  • @scottt2481
    @scottt2481 Год назад

    Excellent as always Chris. Very entertaining compared to the standard THM room. The video contains more insights than the THM room provides. Highly recommend watching the video and don't skip through the answers working from the wording in the room.

  • @romansovetskikh7902
    @romansovetskikh7902 Год назад +2

    Slash in front of dot didn't work in my wireshark. Correct filter appears for me just without slash in this expression.

  • @admar-nelson
    @admar-nelson Год назад +2

    Mr. I know you don't like to make long videos so I suggest you split them into parts and it would also help you to upload them to the youtube platform faster

  • @faran4536
    @faran4536 Год назад +1

    The room was amazing as hell 🔥🔥🔥🔥

  • @admar-nelson
    @admar-nelson Год назад

    I was waiting for this task. thank you so much to provide insight. you are Wireshark Star

  • @igielv
    @igielv 28 дней назад

    Supergood!!! Congratulation Chris and thanks for amazing course.
    I was struggling jut a lil bit to get through Task 6 (Special Operators) - with match / contains filters seems like regex doesn't work properly (at least on macOS).
    - "quotes" has to be used, otherwise syntax is red - incorrect (I know you have them in text, they're just missing from video).
    - "\." is evaluated also as syntax incorrect on macOS - seems like backslash should be omitted and filter works just fine (I know that it's in contrary with regex use, may be a Wireshark bug on macOS, or just a little inconsistency?)
    Many thanx again and have great day everyone.

  • @raymation3d
    @raymation3d Год назад

    Good stuff Chris!!!

  • @kekeke7815
    @kekeke7815 Год назад

    Thankyou for actually explaining tNice tutorialngs. Other videos that I watched started talking about how to make soft and didn't ntion anytNice tutorialng

  • @Immnyy
    @Immnyy Год назад +1

    Cool Chris I love it and i took your course on Udemy

  • @ozzman530
    @ozzman530 Год назад

    Great video. I saved the Site for a rainy day. When I came back to it I noticed some things would not work as described in the walkthrough. Might be due to two newer versions of wireshark having came out since this video was released.

    • @ChrisGreer
      @ChrisGreer  Год назад +2

      You are spot on! The newer versions have different filter syntax and I need to fix the room. My fault here… sorry guys been busy!

  • @ballathiam9486
    @ballathiam9486 Год назад

    Awesome! thank you!

  • @MrBitviper
    @MrBitviper Год назад

    I completed it the same day you posted about that on youtube
    it was great. please create more if you can

    • @ulvihmdli688
      @ulvihmdli688 Год назад

      Hi is this room only for premium members?

    • @MrBitviper
      @MrBitviper Год назад

      @@ulvihmdli688 if I remember correctly this room is free. check out the link with your login and you should be able to access

  • @buf0rd
    @buf0rd Год назад

    Thank you

  • @flinfaraday1821
    @flinfaraday1821 Год назад

    Good stuff. Thanks.
    (maybe trim spaces from answers)

  • @hcetc
    @hcetc Год назад

    Thanks a lot Chris. I am trying to get into the room, but I am unable to. It says the room is private. Kindly guide me.

  • @Rogerson112
    @Rogerson112 Год назад

    Love u thanks for all ❤️

  • @admar-nelson
    @admar-nelson Год назад +1

    In the THM Platform has also some others Wireshark and others PCAP rooms. please put it in your plan too. for now I deep Thanks for provide solution for this room. I made only 72%. now I'll finich it of course 😊😉

    • @ChrisGreer
      @ChrisGreer  Год назад

      Great idea - planning to do more rooms like this.

    • @admar-nelson
      @admar-nelson Год назад

      @@ChrisGreer we'll waiting Mr.

  • @falcon__4316
    @falcon__4316 Год назад

    good one

  • @heavydieselengine8989
    @heavydieselengine8989 Год назад

    ok, am I crazy or what. I put in the IP.addr in with the curly braces and it was not working and only worked if i removed the comma between the IP address?

    • @ChrisGreer
      @ChrisGreer  Год назад

      You aren’t crazy… Wireshark 4.0 now requires “”. So I need to fix that in the room…

    • @heavydieselengine8989
      @heavydieselengine8989 Год назад

      @@ChrisGreer thanks for the info

  • @dandtech
    @dandtech Год назад

    Great room! But I'm not getting any tryhackme points from your room!

    • @ChrisGreer
      @ChrisGreer  Год назад +1

      Yeah I don’t think they give points until they make it public, which is on their release schedule. I’ve asked how long it will take but no answer. Been waiting 6 months ☹️

    • @dandtech
      @dandtech Год назад

      @@ChrisGreer Waw... 6 months! That's brutal... :-(

    • @ChrisGreer
      @ChrisGreer  Год назад +1

      @@dandtech Yeah I know! I got kinda tired of waiting that's why I just released this video. Hope that the traffic to it will trigger their attention!

  • @sorinciobanu4561
    @sorinciobanu4561 Год назад

    It says that room ist privat

  • @Harsh-bl3wq
    @Harsh-bl3wq Год назад +1

    I am an idiot. For Task 6 i was using task 5 pcap instead of task 3 pcap. 😅. I did not read the Instructions.

    • @ChrisGreer
      @ChrisGreer  Год назад

      Sorry I could have made that a little easier on my end too....

  • @sorinciobanu4561
    @sorinciobanu4561 Год назад

    I cant find the room..

    • @ChrisGreer
      @ChrisGreer  Год назад +1

      Is the link working? TryHackMe.com/jr/wiresharkfilters

    • @sorinciobanu4561
      @sorinciobanu4561 Год назад

      @@ChrisGreer Yes, now its working. But the link from description not, at least for me

    • @ChrisGreer
      @ChrisGreer  Год назад

      @@sorinciobanu4561 Ok thanks for the heads up!

  • @net_setup
    @net_setup Год назад +2

    hello...I noticed that on my version of wireshark (4.0.3) I had to use: frame matches ".com|.org" on task 6 question 3 to get the 28 packets. I tried removing the "." in the search also and it worked too. don't know if that will help anyone.

    • @ChrisGreer
      @ChrisGreer  Год назад +1

      Thanks for mentioning that! On the VM on THM they are using an earlier version so the no-quotes works. But not on 4.0 and newer. Thanks for spotting that.