CyberLab-04
This repository documents the analysis of a TCP session hijacking attack against a Telnet session.
The packet capture demonstrates an attacker taking over an active TCP connection by injecting packets after a change in the source MAC address.
- Examine the packet capture using Wireshark.
- Identify the point where the source MAC address changes.
- Identify suspicious network behavior.
- Wireshark 4.x
- Protocol: Telnet (TCP/23)
- Capture Format: PCAP
- Evaluate evidence of TCP session hijacking.
- Identify packet injection
- Detect Layer 2 spoofing