In this post I want to talk about a very essential part of my workflow when
dealing with Bluetooth devices, particularly IoT devices with a corresponding
mobile app: Live capture of Android Bluetooth traffic with Wireshark.
Before you stop reading because you think you know how to do this already, the
method does not involve pulling bug reports off your phone, and it does not
require root. And most importantly it gives you a live packet log in
Wireshark.
Wireshark in IP version 6 workshop was a part of IPv6 summit sessions of
Troopers 16. It was held by Jeffery Carrell on the second day of IPv6 summit on
Tuesday, the 15th of March. The workshop was generally divided into two
sections: a short introduction to IPv6 and analyzing some IPv6 packets on
Wireshark.
Introduction to IPv6
IPv6 protocol was defined at the end of 1990’s, mainly to provide a huge address
pool after realizing that the world would run out of IPv4 addresses quickly. The
work on IPv6 started before the introduction of NAT and Private addressing to
IPv4, which are considered temporary solutions of IPv4 address shortage problem.
IPv6 address consists of 128 bits, divided into 8 groups called nibbles,
quibbles or hextets separated by colons. Each nibble consists of four
hexadecimal digits. The 128 bits address length provides 340 trillion trillion
trillion addresses. An IPv6 address is divided into two parts: the left part is
the network identifier while the right one is the host identifier. The default
prefix is /64 which divided the IP address into two halves. An IPv6 address
looks as follows: 2001:0db8:1010:61ab:f005:ba11:00da:11a5/64