How to detect the real IP addresses of an hacker in ARP Spoofing using Wireshark?

59 views Asked by At

I have this capture in Wireshark (cap5.pcap - https://drive.google.com/file/d/1pK_AXieem7ctEUzjgVJa8sqdaxsaFQgs/view?usp=sharing). It represents an ARP Spoofing attack, for academic purposes. The goal is to find the real IP address of the attacker. Is it possible? Thank you.

I tried to find the most suspicious IP addresses and I found some suspicious activity around the frame number 2100. The IP address 192.168.22.20 looks suspicious but I don't know

0

There are 0 answers