Décortiquer un paquet TLS avec WireShark

Capture d'écran

Nous allons procéder à une analyse détaillée de ce paquet capturé par Wireshark, qui transporte des données d'application chiffrées via TLSv1.2 (le protocole de sécurité utilisé notamment pour HTTPS).


1. La ligne de résumé

No.     Time           Source                Destination           Protocol Length Info
59 34.647305      192.168.10.251        172.64.41.4           TLSv1.2  110    Application Data

2. Détails de la trame (Frame 59)

Frame 59: 110 bytes on wire (880 bits), 110 bytes captured (880 bits) on interface \Device\NPF_{...}, id 0
    Section number: 1
    Interface id: 0 (\Device\NPF_{...})
        Interface name: \Device\NPF_{...}
        Interface description: vEthernet (COM_EXT)
    Encapsulation type: Ethernet (1)
    Arrival Time: Feb  7, 2025 12:03:09.667468000 Paris, Madrid
    UTC Arrival Time: Feb  7, 2025 11:03:09.667468000 UTC
    Epoch Arrival Time: 1738926189.667468000
    [Time shift for this packet: 0.000000000 seconds]
    [Time delta from previous captured frame: 0.047441000 seconds]
    [Time delta from previous displayed frame: 0.047441000 seconds]
    [Time since reference or first frame: 34.647305000 seconds]
    Frame Number: 59
    Frame Length: 110 bytes (880 bits)
    Capture Length: 110 bytes (880 bits)
    [Frame is marked: False]
    [Frame is ignored: False]
    [Protocols in frame: eth:ethertype:ip:tcp:tls]
    [Coloring Rule Name: TCP]
    [Coloring Rule String: tcp]

Ce qui est indiqué ici :


3. En-tête Ethernet

Ethernet II, Src: GigaByteTech_06:75:5d (10:ff:e0:06:75:5d), Dst: Qotom_f5:35:01 (20:7c:14:f5:35:01)
    Destination: Qotom_f5:35:01 (20:7c:14:f5:35:01)
        .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
        .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
    Source: GigaByteTech_06:75:5d (10:ff:e0:06:75:5d)
        .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
        .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
    Type: IPv4 (0x0800)

Explications :


4. En-tête IPv4

Internet Protocol Version 4, Src: 192.168.10.251, Dst: 172.64.41.4
    0100 .... = Version: 4
    .... 0101 = Header Length: 20 bytes (5)
    Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
    Total Length: 96
    Identification: 0x112f (4399)
    010. .... = Flags: 0x2, Don't fragment
    ...0 0000 0000 0000 = Fragment Offset: 0
    Time to Live: 128
    Protocol: TCP (6)
    Header Checksum: 0x4881 [validation disabled]
    Source Address: 192.168.10.251
    Destination Address: 172.64.41.4

Détails :


5. En-tête TCP

Transmission Control Protocol, Src Port: 49780, Dst Port: 443, Seq: 1, Ack: 1, Len: 56

Ce que cela signifie :


6. Couche TLS (Transport Layer Security)

Transport Layer Security

À savoir :


Récapitulatif général


⬆️ Retour en haut de la page