November 2017
Intermediate to advanced
226 pages
5h 59m
English
Now we can try to parse the data that we sniffed, and unpack the headers. To parse a packet, we need to have an idea of the Ethernet frame and the packet headers of the IP.
The Ethernet frame structure is as follows:

The first six bytes are for the Destination MAC address and the next six bytes are for the Source MAC. The last two bytes are for the Ether Type. The rest includes DATA and CRC Checksum. According to RFC 791, an IP header looks like the following:

The IP header includes the following sections:
Read now
Unlock full access