1 / 11
文档名称:

利用wireshark分析DNS.doc

格式:doc   大小:714KB   页数:11页
下载后只包含 1 个 DOC 格式的文档,没有任何的图纸或源代码,查看文件列表

如果您已付费下载过本站文档,您可以点这里二次下载

分享

预览

利用wireshark分析DNS.doc

上传人:mh900965 2017/12/20 文件大小:714 KB

下载得到文件列表

利用wireshark分析DNS.doc

文档介绍

文档介绍:实验目的
域名信息或诊断DNS 服务器。学会使用ipconfig工具进行分析。
会用wireshark分析DNS协议。对DNS协议有个全面的学****与了解。
实验器材
的计算机主机;
2、抓包工具wireshark和截图工具snagit。
三、实验内容
1. Run nslookup to obtain the IP address of a Web server in Asia.
the IP address of :
2. Run nslookup to determine the authoritative DNS servers for a university in Europe.
实验结果如下图:
3. Run nslookup so that one of the DNS servers obtained in Question 2 is queried for
the mail servers for Yahoo! mail.
实验结果如下图:
4. Locate the DNS query and response messages. Are then sent over UDP or TCP?
答:DNS query and response messages如下图标注,
They ate sent over UDP ;
5. What is the destination port for the DNS query message? What is the source port
of DNS response message?
答:the destination port is: 64211(64211)
the source port is:domain(53)
6. To what IP address is the DNS query message sent? Use ipconfig to determine the
IP address of your local DNS server. Are these two IP addresses the same?
答: ,这两个IP地址是一样的。试验截图如下
7. Examine the DNS query message. What “Type” of DNS query is it? Does the
query message contain any “answers”?
答:“Type” of DNS query is(host address)
没有包含“answer”;
8. Examine the DNS response message. How many “answers” are provided? What
do each of these answers contain?
答:“answers”如下图:
9. Consider the subsequent TCP SYN packet sent by your host. Does the destination
IP address of the SYN packet correspond to any of the IP addresses provided in
the DNS response message?
答:
10. This web page contains images. Before retrieving each image, does your host
issue new DNS queries?
答: my hostissue don’t issue new DNS queries。
11. What is the destination port for the DNS query message? What is the source port
of DNS response message?
答:the destination port for the DNS query message:
the source port of DNS response message:
他们是相同的。
12. To what IP address is the DNS query message sent? Is this the IP address of your
default local DNS server?
IP address:
This is the I