PING sweep

Let's begin with our first scenario, where an attacker is trying to perform a ping sweep attack over the subnet his machine is a part of (assumption: The attacker is an internal employee). Refer to the following screenshot, which displays displays the traffic captured as a result of running a bash script (ping sweep scan); the script pings each IP, starting from 192.168.1.100 to 192.168.1.110:

Ping sweep

Starting from packets 1-4, ARP requests are observed because of the ICMP ping command issued on Kali and, as it is fresh network, configuration devices would need to build their ARP cache table for internal LAN communication. In ...

Get Wireshark 2 Quick Start Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.