0% found this document useful (0 votes)
6 views2 pages

Identify SYN Storm Attack IP

The document describes a network incident involving intermittent outages and slowness during lunch hours, prompting an investigation into a packet capture file. The task is to identify the source IP responsible for the attack, with the flag format specified as GEHC{source_IP}. The solution involves using Wireshark to analyze the packet capture and determine the IP with suspiciously high traffic.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views2 pages

Identify SYN Storm Attack IP

The document describes a network incident involving intermittent outages and slowness during lunch hours, prompting an investigation into a packet capture file. The task is to identify the source IP responsible for the attack, with the flag format specified as GEHC{source_IP}. The solution involves using Wireshark to analyze the packet capture and determine the IP with suspiciously high traffic.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Network - SYN Storm on the

Wire - Easy

Your company’s small office network started seeing intermittent outages and
extreme slowness during the lunch hour. The on-call network engineer discovered
a packet capture taken from the gateway during the incident. You — a junior
incident responder — were handed the .pcapng and told: “Find the IP that started
the attack and prove it.
Note: flag format GEHC{source_IP}

Solution
Step 1: Open the given [Link] file in wireshark and open IPv4 statistics

Check from which IP has suspicious high traffic percentage

Network - SYN Storm on the Wire - Easy 1


mentions IP in GEHC{[Link]} as flag and submit it.

Network - SYN Storm on the Wire - Easy 2

You might also like