We are given a packet capture with little description of what to look for. While looking through the UDP streams, I came across two packets with the text start
and end
within in the data section:
Packet 1104:
data:image/s3,"s3://crabby-images/4628e/4628e21bc2ba895633b9faa9a80385e846479a36" alt=""
Packet 1303:
data:image/s3,"s3://crabby-images/6cb29/6cb29a346fe2e2b2a9893d4a3466c001b13dc966" alt=""
The only bytes changing between the start packet (#1104) and the next UDP packet (#1106) were the data field, checksums, and the source port. I noticed that the difference between the source ports of these two packets (5112 - 5000 = 112) was the ASCII code for the letter p
. I repeated this for all the UDP packets (excluding MDNS queries) and found the following numbers: