This website collects cookies to deliver better user experience
dns.cap
-r
wc
-l
$ tshark -r dns.cap | wc -l 38
38
-Y "dns.qry.type == 1"
$ tshark -r dns.cap -Y "dns.qry.type == 1" | wc -l 6
6
-T fields
-e dns.qry.name
$ tshark -r dns.cap -Y "dns.qry.type == 1" -T fields -e dns.qry.name www.netbsd.org www.netbsd.org GRIMM.utelsystems.local GRIMM.utelsystems.local GRIMM.utelsystems.local GRIMM.utelsystems.local
GRIMM.utelsystems.local
$ tshark -r task3.pcap | wc -l 125
125
$ tshark -r task3.pcap -Y "dns.flags.response == 0" | wc -l 56
56
$ tshark -r task3.pcap -Y "dns.flags.response == 0" -T fields -e dns.id 0x0000beef
0x0000beef
$ tshark -r task3.pcap -Y "dns.flags.response == 0" -T fields -e dns.qry.name | cut -c1 | tr "\n" " " | sed 's/ //g' MZWGCZ33ORUDC427NFZV65BQOVTWQX3XNF2GQMDVG5PXI43IGRZGWIL5
MZWGCZ33ORUDC427NFZV65BQOVTWQX3XNF2GQMDVG5PXI43IGRZGWIL5
$ echo 'MZWGCZ33ORUDC427NFZV65BQOVTWQX3XNF2GQMDVG5PXI43IGRZGWIL5' | base32 -d flag{th1s_is_t0ugh_with0u7_tsh4rk!}
flag{th1s_is_t0ugh_with0u7_tsh4rk!}
26
0