Wireshark capture question


Hello, Can someone help to figure out what methods to use to find ip address of the person implementing the teardrop attack and the ip address of the one who is being attacked? Also, how would I figure out the byte numbers that are being replaced by the teardrop attack.

The capture that I am using is the sample teardrop that is found from wiki wireshark;

Any help would be great. Thanks!

