- Hands-On Network Forensics
- Nipun Jaswal
- 295字
- 2021-06-24 16:04:19
Identifying the IP endpoints
Domain names were invented to make it more easy to remember sites with common phrases. Having a list of IP addresses in the previous section would make no sense to us, but having a list that shows the resolution of the IPs into domain names can help us a lot. On clicking the Show address resolution / Resolved Addresses option, we will be presented with the following:

Well, this now makes proper sense, as we have a list of IP addresses with their domain resolutions that can help us eliminate the false positives. We saw in the previous endpoint section that the second-highest number of packets in the endpoints originated from 162.125.34.6. Since we don't have an idea of what IP address this could be, we can easily refer to the address resolutions and figure out that this is dropbox-dns.com, which looks suspicious. Let's search for it on Google using the string client.dropbox-dns.com, and browsing the first result from the search, we have the following result:

We can see from the preceding search result (the official Dropbox website, https://www.dropbox.com/) that the domain is a legitimate Dropbox domain and the traffic originating to and from it is safe (assuming that Dropbox is permitted on the network or if allowed for a select group of users that the traffic is associated with those users only). This resolution not only helps us identify domains, but also speaks a lot about the software running on the target as well. We already identified Dropbox as running on the system. We also identified the following domains from the Resolved Addresses pane in Wireshark:
- A Gmail account being accessed
- A Qihoo 360 antivirus
- An HDFC bank account
- The Grammarly plugin
- The Firefox browser
- 暗戰(zhàn)亮劍:黑客滲透與防御全程實錄
- 工業(yè)物聯(lián)網(wǎng)安全
- 計算機網(wǎng)絡(luò)安全技術(shù)研究
- 學電腦安全與病毒防范
- 情報驅(qū)動應急響應
- 解密數(shù)據(jù)恢復
- 編譯與反編譯技術(shù)實戰(zhàn)
- 黑客攻防從入門到精通
- 黑客攻防實戰(zhàn)從入門到精通
- 交換機·路由器·防火墻(第2版)
- 黑客攻防從入門到精通:命令版
- 密碼朋克:自由與互聯(lián)網(wǎng)的未來
- 數(shù)據(jù)恢復技術(shù)深度揭秘
- 企業(yè)安全建設(shè)入門:基于開源軟件打造企業(yè)網(wǎng)絡(luò)安全
- 大中型網(wǎng)絡(luò)入侵要案直擊與防御