Packets
DNS
Networking quirks
TCP
MISC
100

How many HTTP packets are there in the Ultimate PCAP?

What is 56?

100
What type of record are we looking for in 13167?

What is TXT

100

Which VLANs do we see in the packets from router cisco_19:03:44

What is 7?

100

What is the smallest TCP Header size, and what is the biggest?

What is 20 and 60 bytes?

100

What is the full MAC Address of the client involved in the SSH traffic?

What is 00:1e:7a:79:3f:11?

200

This packet has these properties

host = ip.webernetz.net, Destination = 212.144.254.123

What is 17

200

How much DNS traffic goes to and from 9.9.9.9

154

200

How many updates are sent with the Border Gateway Protocol with length 187?

What is 2?
200

What's a Packet from Mars?

Traffic from reserved (unused) IP space.

200

What's the telnet password and what packet contains the final character of it?

What is L35jFNz0Z4Ao8X6x4Uic / 21808

300

Days from first to last packet captured.

What is 2225 days?

300

What is the packet number of the first time we ask for the entire alphabet in a DNS request?

What is 13168?

300

What's the packet number of the informational ISAKMP packet with c8ad1cefe63daf36 as a SPI value?

What is 6039?

300

What's the display filter syntax that removes TCP packets with "asdfasdf"?

What is not (tcp contains "asdfsadf") or !tcp contains "asdfasdf"

300

Find the noisy apple device in the UDP streams.

What's an Johannes-Ei-patt?

400

The first packet that announces the presence of a IPv6 router, packet length is 174.

What is 21190?

400

Which DNS server do we ask to resolve foobar.sshfp.net?

What is 2620:fe::fe

400

How many ESP packets contain 0xfb

What is 542?

400

Which 2 2 byte long fields in the TCP header can be used to exfiltrate data in a very sneaky way?

What is WINDOW SIZE & URGENT POINTER?

400

Resolve 70:b3:d5:66:80:00 to a hostname.

What is Öresunds?

500

What packet contains favicon.ico and what does it look like?

12681, a W?

500

What's the packet number for the DNS "refused" response?

What is 559?

500

What is the local time in the first NTP packet with a packetnumber > 1000

20:57:47 Roman Standard.

500

What flag will this capture filter look for? 

TCP[13] & xx == yy

What is RST?
500

Which game from 1996 can wireshark natively decode data from and for example show frags and player colors?

What is Quake.

M
e
n
u