{"id":731,"date":"2020-04-26T07:54:51","date_gmt":"2020-04-26T05:54:51","guid":{"rendered":"http:\/\/tech.sosthe.sk\/?p=731"},"modified":"2020-04-26T08:40:32","modified_gmt":"2020-04-26T06:40:32","slug":"sietove-nastroje","status":"publish","type":"post","link":"http:\/\/tech.sosthe.sk\/index.php\/2020\/04\/26\/sietove-nastroje\/","title":{"rendered":"WIRESHARK"},"content":{"rendered":"<p>Wireshark je open-source n\u00e1stroj sl\u00fa\u017eiaci prim\u00e1rne na odchyt\u00e1vanie a anal\u00fdzu sie\u0165ovej prev\u00e1dzky. \u010casto sa vyu\u017e\u00edva pri troubleshootingu, vzdel\u00e1van\u00ed, alebo m\u00f4\u017ee posl\u00fa\u017ei\u0165 hackerovi napr\u00edklad pri\u00a0odchyt\u00e1van\u00ed hesla.<\/p>\n<p>Wireshark si m\u00f4\u017eete zadarmo stiahnu\u0165\u00a0<strong><a href=\"https:\/\/www.wireshark.org\/#download\">tu<\/a>.\u00a0<\/strong>Funguje na opera\u010dn\u00fdch syst\u00e9moch Windows, Linux aj macOS. In\u0161taluje sa ako be\u017en\u00fd program. Pri in\u0161tal\u00e1cii nie je potrebn\u00e9 meni\u0165 nastavenia, skr\u00e1tka sa treba len &#8222;preklika\u0165&#8220; a\u017e na koniec in\u0161tal\u00e1cie. Po nain\u0161talovan\u00ed sa objav\u00ed ikonka modrej \u017eralo\u010dej plutvy, pomocou ktorej program sp\u00fa\u0161\u0165ame.\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-734 aligncenter\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/sharkico.png\" alt=\"\" width=\"80\" height=\"90\" \/>Po spusten\u00ed sa zobraz\u00ed okno programu naj\u010dastej\u0161ie v nasledovnom tvare:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-735 \" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/wireshark.png\" alt=\"\" width=\"488\" height=\"328\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/wireshark.png 995w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/wireshark-300x201.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/wireshark-768x516.png 768w\" sizes=\"(max-width: 488px) 100vw, 488px\" \/><\/p>\n<p>V polo\u017eke Capture vid\u00edte zoznam sie\u0165ov\u00fdch rozhran\u00ed s krivkou aktivity. M\u00f4\u017eete si v\u0161imn\u00fa\u0165, \u017ee po\u010d\u00edta\u010d je pripojen\u00fd do siete cez Wi-Fi rozhranie. Z ponuky si vyberiete sk\u00faman\u00e9 sie\u0165ov\u00e9 rozhranie a spust\u00edte odchyt\u00e1vanie paketov.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-736 \" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/wireshark_go.png\" alt=\"\" width=\"489\" height=\"328\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/wireshark_go.png 995w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/wireshark_go-300x201.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/wireshark_go-768x516.png 768w\" sizes=\"(max-width: 489px) 100vw, 489px\" \/><\/p>\n<p>Zobraz\u00ed sa v\u00e1m okno programu rozdelen\u00e9 na tri \u010dasti. V hornej \u010dasti uvid\u00edte jednotliv\u00e9 stiahnut\u00e9 pakety. S\u00fa farebne rozl\u00ed\u0161en\u00e9 pod\u013ea typu pou\u017eit\u00e9ho protokolu. V strednej \u010dasti je v\u00fdpis hlavi\u010dky vybran\u00e9ho paketu a v spodnej \u010dasti v\u00fdpis d\u00e1t v pakete. Aby sme programom mohli analyzova\u0165 stiahnut\u00e9 pakety je potrebn\u00e9 odchyt\u00e1vanie zastavi\u0165. Tla\u010d\u00edtka stop a \u0161tart pre odchyt\u00e1vanie n\u00e1jdete na n\u00e1strojovej li\u0161te.<\/p>\n<p>Ak odchyt\u00e1vame v\u0161etku prev\u00e1dzku z nejak\u00e9ho rozhrania, dostaneme vo v\u00fdslednom s\u00fabore zmes komunik\u00e1cie prostredn\u00edctvom r\u00f4znych protokolov, ako ARP, ICMP, SNMP a pod., ktor\u00e9 n\u00e1s nemusia v danej chv\u00edli zauj\u00edma\u0165. Aby sme odfiltrovali iba komunik\u00e1ciu, ktor\u00e1 n\u00e1s zauj\u00edma, napr\u00edklad na z\u00e1klade zdrojovej, alebo cie\u013eovej IP adresy, alebo na z\u00e1klade protokolu, m\u00f4\u017eeme si nastavi\u0165 filter. Ni\u017e\u0161ie uv\u00e1dzam Wireshark filtre, ktor\u00e9 s\u00fa pou\u017e\u00edvan\u00e9 naj\u010dastej\u0161ie.<\/p>\n<h4>Filtrovanie celej komunik\u00e1cie jednej IP adresy<\/h4>\n<p>Nasledovn\u00fd filter n\u00e1m vytriedi prev\u00e1dzku, kde zadan\u00e1 IP adresa m\u00f4\u017ee by\u0165 zdrojov\u00e1, alebo cie\u013eov\u00e1.<\/p>\n<pre>ip.addr == 192.168.1.145<\/pre>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-737 size-full\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/21-address.png\" alt=\"\" width=\"976\" height=\"117\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/21-address.png 976w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/21-address-300x36.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/21-address-768x92.png 768w\" sizes=\"(max-width: 976px) 100vw, 976px\" \/><\/h2>\n<h4>Filtrovanie na z\u00e1klade zdrojovej IP adresy<\/h4>\n<pre>ip.src == 192.168.1.4<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-738 size-full\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/22-src-ip.png\" alt=\"\" width=\"949\" height=\"118\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/22-src-ip.png 949w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/22-src-ip-300x37.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/22-src-ip-768x95.png 768w\" sizes=\"(max-width: 949px) 100vw, 949px\" \/><\/p>\n<h4>Filtrovanie na z\u00e1klade cie\u013eovej IP adresy<\/h4>\n<pre>ip.dst == 192.168.1.145<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-739 size-full\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/23.-dst-ip.png\" alt=\"\" width=\"939\" height=\"113\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/23.-dst-ip.png 939w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/23.-dst-ip-300x36.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/23.-dst-ip-768x92.png 768w\" sizes=\"(max-width: 939px) 100vw, 939px\" \/><\/p>\n<h4>Filtrovanie na z\u00e1klade subnetu<\/h4>\n<p>Nasledovn\u00fd filter n\u00e1m vytriedi prev\u00e1dzku, kde je zdrojov\u00e1, alebo cie\u013eov\u00e1 IP adresa z definovan\u00e9ho rozsahu.<\/p>\n<pre>ip.src == 192.168.1.0\/24<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-740 size-full\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/24-src-net.png\" alt=\"\" width=\"943\" height=\"134\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/24-src-net.png 943w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/24-src-net-300x43.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/24-src-net-768x109.png 768w\" sizes=\"(max-width: 943px) 100vw, 943px\" \/><\/p>\n<h4>Filtrovanie na z\u00e1klade MAC adresy<\/h4>\n<pre>eth.dst == 00:90:a9:41:2a:39<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-741 size-full\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/7.-mac-addr.png\" alt=\"\" width=\"893\" height=\"129\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/7.-mac-addr.png 893w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/7.-mac-addr-300x43.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/7.-mac-addr-768x111.png 768w\" sizes=\"(max-width: 893px) 100vw, 893px\" \/><\/p>\n<h4>Filtrovanie na z\u00e1klade slu\u017eby<\/h4>\n<p>Ak chceme filtrova\u0165 prev\u00e1dzku na z\u00e1klade protokolu, m\u00f4\u017eeme bu\u010f zada\u0165 priamo jeho n\u00e1zov, alebo TCP\/UDP port, na ktorom prebieha komunik\u00e1cia.<\/p>\n<pre>tcp.port == 21<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-742 size-full\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/5.-tcp-port.png\" alt=\"\" width=\"865\" height=\"133\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/5.-tcp-port.png 865w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/5.-tcp-port-300x46.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/5.-tcp-port-768x118.png 768w\" sizes=\"(max-width: 865px) 100vw, 865px\" \/><\/p>\n<pre>ftp<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-743 size-full\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/6.-ftp.png\" alt=\"\" width=\"824\" height=\"156\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/6.-ftp.png 824w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/6.-ftp-300x57.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/6.-ftp-768x145.png 768w\" sizes=\"(max-width: 824px) 100vw, 824px\" \/><\/p>\n<h4>Porovn\u00e1vanie hodn\u00f4t<\/h4>\n<p>V pr\u00edkladoch uveden\u00fdch vy\u0161\u0161ie m\u00f4\u017eeme vidie\u0165 pou\u017eitie oper\u00e1tora \u201crovn\u00e1 sa\u201d. V nasledovnej tabu\u013eke s\u00fa uveden\u00e9 \u010fal\u0161ie oper\u00e1tory, ktor\u00e9 m\u00f4\u017eeme vyu\u017ei\u0165 pri filtrovan\u00ed.<\/p>\n<table id=\"tablepress-11\" class=\"tablepress tablepress-id-11\" style=\"width: 37.2515%;\">\n<tbody class=\"row-hover\">\n<tr class=\"row-1 odd\">\n<td class=\"column-1\" style=\"width: 72.6368%; border-style: solid;\">rovn\u00e1 sa<\/td>\n<td class=\"column-2\" style=\"width: 12.5259%; border-style: solid;\">\u2a75<\/td>\n<td class=\"column-3\" style=\"width: 57.117%; border-style: solid;\">eq<\/td>\n<\/tr>\n<tr class=\"row-2 even\">\n<td class=\"column-1\" style=\"width: 72.6368%; border-style: solid;\">nerovn\u00e1 sa<\/td>\n<td class=\"column-2\" style=\"width: 12.5259%; border-style: solid;\">!=<\/td>\n<td class=\"column-3\" style=\"width: 57.117%; border-style: solid;\">ne<\/td>\n<\/tr>\n<tr class=\"row-3 odd\">\n<td class=\"column-1\" style=\"width: 72.6368%; border-style: solid;\">v\u00e4\u010d\u0161ie ako<\/td>\n<td class=\"column-2\" style=\"width: 12.5259%; border-style: solid;\">&gt;<\/td>\n<td class=\"column-3\" style=\"width: 57.117%; border-style: solid;\">gt<\/td>\n<\/tr>\n<tr class=\"row-4 even\">\n<td class=\"column-1\" style=\"width: 72.6368%; border-style: solid;\">men\u0161ie ako<\/td>\n<td class=\"column-2\" style=\"width: 12.5259%; border-style: solid;\">&lt;<\/td>\n<td class=\"column-3\" style=\"width: 57.117%; border-style: solid;\">lt<\/td>\n<\/tr>\n<tr class=\"row-5 odd\">\n<td class=\"column-1\" style=\"width: 72.6368%; border-style: solid;\">v\u00e4\u010d\u0161ie, alebo rovn\u00e9<\/td>\n<td class=\"column-2\" style=\"width: 12.5259%; border-style: solid;\">&gt;=<\/td>\n<td class=\"column-3\" style=\"width: 57.117%; border-style: solid;\">ge<\/td>\n<\/tr>\n<tr class=\"row-6 even\">\n<td class=\"column-1\" style=\"width: 72.6368%; border-style: solid;\">men\u0161ie, alebo rovn\u00e9<\/td>\n<td class=\"column-2\" style=\"width: 12.5259%; border-style: solid;\">&lt;=<\/td>\n<td class=\"column-3\" style=\"width: 57.117%; border-style: solid;\">le<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4>Logick\u00e9 oper\u00e1tory<\/h4>\n<p>Ak potrebujeme zada\u0165 \u0161pecifickej\u0161\u00ed filter zadan\u00edm viacer\u00fdch podmienok, m\u00f4\u017eeme tak spravi\u0165 pou\u017eit\u00edm nasledovn\u00fdch logick\u00fdch oper\u00e1torov.<\/p>\n<table id=\"tablepress-12\" class=\"tablepress tablepress-id-12\" style=\"width: 17%;\">\n<tbody class=\"row-hover\">\n<tr class=\"row-1 odd\">\n<td class=\"column-1\" style=\"width: 50%; border-style: solid;\">and<\/td>\n<td class=\"column-2\" style=\"width: 31.25%; border-style: solid;\">&amp;&amp;<\/td>\n<\/tr>\n<tr class=\"row-2 even\">\n<td class=\"column-1\" style=\"width: 50%; border-style: solid;\">or<\/td>\n<td class=\"column-2\" style=\"width: 31.25%; border-style: solid;\">||<\/td>\n<\/tr>\n<tr class=\"row-3 odd\">\n<td class=\"column-1\" style=\"width: 50%; border-style: solid;\">xor<\/td>\n<td class=\"column-2\" style=\"width: 31.25%; border-style: solid;\">^^<\/td>\n<\/tr>\n<tr class=\"row-4 even\">\n<td class=\"column-1\" style=\"width: 50%; border-style: solid;\">not<\/td>\n<td class=\"column-2\" style=\"width: 31.25%; border-style: solid;\">!<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>V nasledovnom pr\u00edklade je uveden\u00e1 zlo\u017een\u00e1 podmienka, ktor\u00e1 filtruje prev\u00e1dzku s\u00favisiacu s IP adresou 192.168.1.145, alebo 195.168.1.4 a z\u00e1rove\u0148 prebieha na TCP porte 21, \u010di\u017ee ide o FTP prev\u00e1dzku.<\/p>\n<pre>(ip.addr == 192.168.1.145 || ip.addr == 192.168.1.4 ) &amp;&amp; tcp.port == 21<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-744 size-full\" src=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/8.-zlozene-podmienky.png\" alt=\"\" width=\"970\" height=\"155\" srcset=\"http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/8.-zlozene-podmienky.png 970w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/8.-zlozene-podmienky-300x48.png 300w, http:\/\/tech.sosthe.sk\/wp-content\/uploads\/2020\/04\/8.-zlozene-podmienky-768x123.png 768w\" sizes=\"(max-width: 970px) 100vw, 970px\" \/><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wireshark je open-source n\u00e1stroj sl\u00fa\u017eiaci prim\u00e1rne na odchyt\u00e1vanie a anal\u00fdzu sie\u0165ovej prev\u00e1dzky. \u010casto sa vyu\u017e\u00edva pri troubleshootingu, vzdel\u00e1van\u00ed, alebo m\u00f4\u017ee posl\u00fa\u017ei\u0165 hackerovi napr\u00edklad pri\u00a0odchyt\u00e1van\u00ed hesla.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"_links":{"self":[{"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/posts\/731"}],"collection":[{"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/comments?post=731"}],"version-history":[{"count":4,"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/posts\/731\/revisions"}],"predecessor-version":[{"id":746,"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/posts\/731\/revisions\/746"}],"wp:attachment":[{"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/media?parent=731"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/categories?post=731"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/tech.sosthe.sk\/index.php\/wp-json\/wp\/v2\/tags?post=731"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}