Week 12
What are the intervals of time between the transmissions of the beacon frames for Linksys_ses_24086 access point?
.102400 [Seconds]
What are the intervals of time between the transmissions of the beacon frames the from the 30 Munroe St. Access point?
.102400 [Seconds]
Which MAC address in this fame corresponds to the wireless host (give the hexadecimal representation of the MAC address for the host)?
00 13 02 d1 b6 4f
Which MAC address in this fame corresponds to the first hop router?
00 16 b6 f4 eb a8
Which MAC address in this fame corresponds to the first hop router? (give the hexadecimal representation of the MAC address for the host)
00 16 b6 f4 eb a8
What (in hexadecimal notation) is the MAC BSS id on the beacon frame from 30 Munroe St.?
00 16 b6 f7 1d 51
What (in hexadecimal notation) is the source MAC address on the beacon frame from the 30 Munroe St?
00 16 b6 f7 1d 51
Which MAC address in this fame corresponds to the access point (give the hexadecimal representation of the MAC address for the access point)?
00 16 b6 f7 1d 51
Which MAC address in this fame corresponds to the access point?
00 16 b6 f7 1d 51
What is the receiver MAC address in these frames?
00:12:f0:1f:57:13
What is the sender MAC address in the probe request frames?
00:12:f0:1f:57:13
Find the 802.11 frame containing the SYN TCP segment for the first TCP session (alice.txt download) and answer the following questions.
00:13:02:d1:b6:4f, 00:16:b6:f7:1d:51, 00:16:b6:f4:eb:a8
What is the BSS ID MAC address in these frames?
00:16:b6:f7:1d:51
What is the sender MAC address in these frames?
00:16:b6:f7:1d:51
The beacon frames from the 30 Munroe St access point advertise that the access point can support four data rates. What are these rates?
1 (B), 2(B), 5.5(B), 11(B) [Mbit/sec]
What transmission rates are the AP willing to use?
1(B), 2(B), 5.5(B), 11(B)
What transmission rates are the host willing to use?
1(B), 2(B), 5.5(B), 11(B), 6(B), 9, 12(B), 18
What is the destination IP address?
128.119.245.12
Examine the trace file and look for AUTHENTICATION frames sent from the host to an AP and vice versa. How many AUTHENTICATION messages are sent from the wireless host to the Linksys_ses_24086 AP starting at around t = 49?
15
What is the IP address of the wireless host sending this TCP segment?
192.168.1.109
The beacon frames from the 30 Munroe St access point advertise that the access point can support eight extended data rates. What are these rates?
6(B), 9, 12(B), 18, 24(B), 36, 48, 54, [Mbit/sec]
Consider what happens as the host gives up trying to associate with the Linksys_ses_24086 AP and now tries to associate with the 30 Munroe St AP. Look for AUTHENTICATION frames sent from the host to and from the AP and vice versa. At what times are there an AUTHENTICATION frame from the host to the 30 Munroe St. AP?
63.168087, 63.169707
When is there a reply AUTHENTICATION sent from the AP to the host in reply? (wlan.fc.subtype == 11and wlan.fc.type == 0 and wlan.addr == 00:13:02:d1:b6:4f will filter for AUTHENTICATION frames)
63.169071, 63.170692
An ASSOCIATE REQUEST from host to AP, and a corresponding ASSOCIATE RESPONSE frame from AP to host are used for the host to associate with an AP. At what time is there an ASSOCIATE REQUEST from host to the 30 Munroe St AP?
63.169910
When is the corresponding ASSOCIATE REPLY sent?
63.192101
Which MAC address in this fame corresponds to the wireless host?
91 2a b0 49 b6 4f
Find the 802.11 frame containing the SYNACK segment for this TCP Session. Use this frame to answer the next five questions. What are three MAC address fields (in hex) in the 802.11 frame?
91 2a b0 49 b6 4f, 00 16 b6 f7 1d 51, 00 16 b6 f4 eb a8
What is the purpose of a Probe Request frame?
A frame sent by a client station requesting information from either a specific access point, specified by SSID, or all access points in the area, specified with the broadcast SSID.
What is the purpose of a probe response?
A reply to the client from the access point with supported communication information such as transmission rates.
What two actions are taken (frames are sent) by the host in the trace just after t49, to end the association with the 30 Munroe St. AP that was initially in place when trace collection began?
DHCP Release, Deauthentication
Looking at the 802.11 specification, is there another frame that you might have expected to see, but don't see here?
Disassociation
Does the trace contain a reply to the AUTHENTICATION from the Linksys_ses_24086 AP in the trace?
False
Does this destination IP address correspond to the host, access point, first hop router, or some other network-attached device?
First Hop Router
What are the SSIDs of the two access points that are issuing most of the beacon frames in this trace?
Linksys12 and 30 Munroe St
Does the host want the authentication to require a key or be open?
Open
Does the sender MAC address in the frame correspond to the IP address of the device that sent the TCP segment encapsulated within this datagram?
True
What (in hexadecimal notation) is the destination MAC address on the beacon frame from 30 Munroe St.?
ff ff ff ff ff ff
What is the BSS ID MAC address in the probe request frames?
ff:ff:ff:ff:ff:ff
What is the receiver MAC address in the probe request frames?
ff:ff:ff:ff:ff:ff