This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

What is going on here! Wireshark capture analysis.

0

Just started Wireshark and loving it so far, slowly working my way through the documentation and getting the hang of it, however, I was wondering if a guru could give me a bit of advice to what is going on in these two instances.

Firstly, 192.168.1.3 is appearing a lot, what is it? I don't believe I have a .3 full stop, somebodies Laptop or something maybe?

192.168.1.254   192.168.1.255   NBNS    92  Name query NB HOME<1d>
192.168.1.3 224.0.0.1   IGMPv3  60  Membership Query, general
192.168.1.254   224.0.0.1   IGMPv3  60  Membership Query, general
192.168.1.254   192.168.1.255   BROWSER 271 Host Announcement BTHUB3, Workstation, Server, Print Queue Server, Xenix Server, NT Workstation, NT Server, Potential Browser, DFS server
192.168.1.3 224.0.0.1   IGMPv3  60  Membership Query, general
192.168.1.254   224.0.0.1   IGMPv3  60  Membership Query, general
192.168.1.3 224.0.0.1   IGMPv3  60  Membership Query, general
192.168.1.254   192.168.1.255   NBNS    92  Name query NB HOME<1d>
Sagemcom_c1:bc:c3   Broadcast   ARP 60  Who has 192.168.1.254? Tell 192.168.1.3
192.168.1.254   224.0.0.1   IGMPv3  60  Membership Query, general
192.168.1.3 224.0.0.1   IGMPv3  60  Membership Query, general
192.168.1.3 192.168.1.255   BROWSER 271 Local Master Announcement BTHUB3, Workstation, Server, Print Queue Server, Xenix Server, NT Workstation, NT Server, Master Browser, DFS server
192.168.1.3 192.168.1.255   BROWSER 249 Domain/Workgroup Announcement HOME, NT Workstation, Domain Enum
192.168.1.3 224.0.0.1   IGMPv3  60  Membership Query, general
192.168.1.254   192.168.1.255   NBNS    92  Name query NB HOME<1d>

and secondly this below as I am struggling to work out what 192.168.1.71 actually is on my network either ha :-(

192.168.1.71    192.168.1.255   NBNS    110 Registration NB <01>
192.168.1.71    192.168.1.255   NBNS    110 Registration NB UOD<00>
192.168.1.71    192.168.1.255   NBNS    92  Name query NB ISATAP<00>
192.168.1.71    255.255.255.255 DHCP    342 DHCP Inform   - Transaction ID 0x2de5bfde
192.168.1.71    192.168.1.255   NBNS    92  Name query NB UOD<1c>
192.168.1.71    192.168.1.255   NBNS    92  Name query NB ISATAP<00>
192.168.1.71    192.168.1.255   NBNS    92  Name query NB UOD<1c>
192.168.1.71    192.168.1.255   BROWSER 220 Request Announcement OLGA-HP
192.168.1.71    192.168.1.255   BROWSER 243 Host Announcement OLGA-HP, Workstation, Server, Print Queue Server, NT Workstation, Potential Browser
192.168.1.71    255.255.255.255 DHCP    342 DHCP Inform   - Transaction ID 0x2de5bfde
192.168.1.71    192.168.1.255   NBNS    92  Name query NB ISATAP.HOME<00>
192.168.1.71    192.168.1.255   NBNS    92  Name query NB UOD<1c>
192.168.1.71    192.168.1.255   NBNS    92  Name query NB ISATAP.HOME<00>
192.168.1.71    192.168.1.255   BROWSER 232 Browser Election Request
192.168.1.71    192.168.1.255   NBNS    92  Name query NB ISATAP.HOME<00>
192.168.1.71    192.168.1.255   NBNS    92  Name query NB ISATAP.HOME<00>
192.168.1.71    192.168.1.255   NBNS    110 Registration NB <01><02>__MSBROWSE__<02><01>
192.168.1.71    192.168.1.255   NBNS    110 Registration NB <01><02>__MSBROWSE__<02><01>
192.168.1.71    192.168.1.255   NBNS    110 Registration NB <01><02>__MSBROWSE__<02><01>
192.168.1.71    192.168.1.255   BROWSER 220 Request Announcement OLGA-HP
Print Queue Server, NT Workstation, Potential Browser, Master Browser
192.168.1.71    192.168.1.255   BROWSER 250 Domain/Workgroup Announcement UOD, NT Workstation, Domain Enum
192.168.1.71    192.168.1.255   BROWSER 243 Local Master Announcement OLGA-HP, Workstation, Server, 
192.168.1.71    255.255.255.255 UDP 82  49156 → 1947  Len=40
192.168.1.71    255.255.255.255 UDP 82  49156 → 1947  Len=40

Any help would greatly appreciated.

Kind Regards,

Hit.

asked 08 Aug '16, 07:11

hitmanshark's gravatar image

hitmanshark
6113
accept rate: 0%

edited 08 Aug '16, 07:57

Jaap's gravatar image

Jaap ♦
11.7k16101


One Answer:

0

The ARP request from .3 in this line Sagemcom_c1:bc:c3 Broadcast ARP 60 Who has 192.168.1.254? Tell 192.168.1.3 gives a little clue in the MAC address belongs to SAGEMCOM who make broadband and energy products.

Similarly, if you inspect the MAC address for .71 that might give you a clue. As you have posted text excerpts rather than the actual capture file we can't help you any further with that. The capture file allows us to see all the contents of the traffic which helps a lot when investigating issues.

answered 08 Aug '16, 07:57

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

Hello Sir,

Thank you very much for your help.

Sagemcom, Sky Routers. Which I have one currently at 192.168.1.254, Sagemcom_57:f2:f0.

Sagemcom_c1:bc:c8   Broadcast   ARP 60  Who has 192.168.1.254? Tell 192.168.1.3

So from this, can I deduce there has been another potentional Sky Sagemcom router connected?

Regarding the .71 connection, just looking at the capture now, it relates to a MAC: IntelCor_b3:5c:f2, which I am assuming is just a NIC?

Looking at what .71 is doing, is there anyway I can deduce what exactly? As I don't see this anywhere on any other machine connected?

Much appreciated.

Kind Regards,

Hit.

(08 Aug '16, 08:14) hitmanshark

There are a couple more lines from .3 indicating it's likely to be a BT Hub making Windows filesharing announcements in the workgroup "HOME":

192.168.1.3 192.168.1.255   BROWSER 271 Local Master Announcement BTHUB3, Workstation, Server, Print Queue Server, Xenix Server, NT Workstation, NT Server, Master Browser, DFS server
192.168.1.3 192.168.1.255   BROWSER 249 Domain/Workgroup Announcement HOME, NT Workstation, Domain Enum

As for .71, it's also making windows filesharing announcements giving it's name as OLGA-HP in workgroup "UOD":

192.168.1.71    192.168.1.255   BROWSER 243 Host Announcement OLGA-HP, Workstation, Server, Print Queue Server, NT Workstation, Potential Browser
192.168.1.71    192.168.1.255   BROWSER 250 Domain/Workgroup Announcement UOD, NT Workstation, Domain Enum
(08 Aug '16, 08:23) grahamb ♦