Hands-On Network Forensics
上QQ阅读APP看书,第一时间看更新

Questions and exercises

To improve your confidence in your network forensics skills, try answering the following questions:

  1. What is the difference between the ftp and ftp-data display filter in Wireshark?
  2. Can you build an http filter for webpages with specific keywords?
  3. We saved files from the PCAP using NetworkMiner. Can you do this using Wireshark? (Yes/No)
  4. Try repeating these exercises with Tshark.