Networking › Module 3 › Lesson 4
Lab — Wireshark Packet Analysis
Capture and inspect your own traffic with Wireshark—ethically
Opening
See the packets behind the apps
Wireshark turns invisible network conversations into readable frames. Analysts use it to confirm DNS answers, spot cleartext HTTP, and verify TLS handshakes. In this lab you capture only your own traffic—never sniff others without permission.
1. Ethics First
Capture only on interfaces and networks you own or are explicitly authorized to monitor. Sniffing traffic on school, office, or public Wi-Fi without approval can violate policy and law. This lab uses your machine, your browser, and your DNS queries.
2. Setup
1. Install Wireshark (wireshark.org) on your VM, lab PC, or WSL with a GUI. 2. Select your active interface (Wi-Fi or Ethernet—not loopback unless testing localhost). 3. Start capture, then generate traffic in another window.
3. Generate and Filter Traffic
Generate traffic (run while capturing)nslookup cyberlium.com curl http://example.com curl -I https://cyberlium.com
nslookup cyberlium.com curl http://example.com curl -I https://cyberlium.com
Wireshark display filtersdns http tls.handshake
dns http tls.handshake
Click a DNS response and note the A record IP. On an HTTP packet, expand Hypertext Transfer Protocol and read the request line.
4. What to Document
DNS query
Query name, response code, and resolved IPv4 address.
HTTP vs HTTPS
Could you read HTTP headers in cleartext? TLS packets should show encrypted application data.
Ports
Complete Wireshark Packet Lab
Capture at least 30 seconds of your own traffic. Apply dns and http or tls filters. Save a screenshot or short notes showing one DNS answer and one HTTPS (TLS) handshake. Store notes in ~/cyberlium-lab/wireshark-notes.txt.