Using Wireshark to capture and analyze DNS traffic
–Use ipconfig to empty the DNS cache in your host.
•ipconfig /flushdns
–Lookup and Reverse lookup host “www.sanook.com”
•Capture Filter or Display Filter ?
•Locate the DNS query and response messages. Are they sent over UDP or TCP?
•What is the destination port for the DNS query message? What is the source port of DNS response message?
•IP Address for the host www.sanook.com ?
•Queries type for Lookup and Reverse lookup?
•The host names and IP Address of the authoritative DNS