Chaosreader quickly parsed the evidence03.pcap file into a set of sessions. Expand (unzip) the .gz files to read the XML files (necessary to learn what is defined by “preview-url” and “price-display”). In an empty folder, run:
C:\perl\bin\perl.exe chaosreader -v ..\evidence03.pcap
1. What is the MAC address of Ann’s AppleTV?
2. What User-Agent string did Ann’s AppleTV use in HTTP requests?
3. What were Ann’s first four search terms on the AppleTV (all incremental searches count)?
4. What was the title of the first movie Ann clicked on?
5. What was the full URL to the movie trailer (defined by “preview-url”)?
6. What was the title of the second movie Ann clicked on?
7. What was the price to buy it (defined by “price-display”)?
8. What was the last full term Ann searched for?
MAC address of router:
Note: NetworkMiner parsed the pcap file, but results were not particularly easy to use.