This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello guys,

I'm not much of an expert and I'm stuck. What I wanna do is:

  • I have a captured TCP stream in pcap
  • I wanna separate Client and Server connection
  • Extract the payload/Application Data (Not decrypt or stuff like that)
  • And replay the extracted payload. For example with Packet Sender which is taking care of the connection sequence
  • If possible automatically, because there usually over 150 packets

I don't wanna change the IP-Address necessarily.

I tried tcpprep to split the packets and tcpwrite create a new pcap file. But it didn't work out. The background behind all this, it is a research for my study program and I need to perform a replay attack.

If you could help me, it would be very sweet. Thx in advance....

asked 25 Oct '17, 08:37

UserWire's gravatar image

UserWire
11112
accept rate: 0%

No one or is it too trivial??!

(26 Oct '17, 09:56) UserWire

I don't understand when you say you want to extract the payload but not decrypt for replay. If you extract the encrypted payload you won't be able to replay that as the TLS handshake will fail.

(26 Oct '17, 12:05) grahamb ♦

The Handshake will be taken care of by the tool Packet Sender. It will manage the connection. I just need to fill the packets with the encrypted payload. Thats the big advantage of replay-attacks, unless there aren't any replay-countermeasures like sessionID or timestamps. You don't need any decryption, just the bitstream.

Or am I wrong?! I presented this idea my Prof. and he didn't oppose to that, so I am a lil confused right now.

Thanks for your reply.

permanent link

answered 26 Oct '17, 13:56

UserWire's gravatar image

UserWire
11112
accept rate: 0%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×752
×238
×58

question asked: 25 Oct '17, 08:37

question was seen: 694 times

last updated: 26 Oct '17, 13:56

p​o​w​e​r​e​d by O​S​Q​A