Map IP Address Locations with Wireshark (Using GeoIP)

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 ก.ย. 2024
  • Where is an attacker coming from? Using wireshark and GeoIP databases, we can map out IP locations (unless they are spoofed of course) to a browser with a click of a button. How?
    First - you have to register and download the GeoIP Lite Databases (Free):
    dev.maxmind.co...
    Then, point Wireshark to the databases, look up endpoints, then toss them out to a map. Boom! You're done.
    Like this video? Then show it! Please smash like and share it with all your IT buddies. That really helps me out.
    Other links n' stuff:
    == More On-Demand Training from Chris ==
    ▶Getting Started with Wireshark - bit.ly/udemywi...
    ▶Getting Started with Nmap - bit.ly/udemynmap
    == Live Wireshark Training ==
    ▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtual...
    == Private Wireshark Training ==
    Let's get in touch - packetpioneer....
    Special thanks to my cat, Pepé for his video-bomb!

ความคิดเห็น • 183

  • @josealexander5992
    @josealexander5992 18 วันที่ผ่านมา +1

    Very comprehensive & informative, easy to understand/follow. What was initially a intimidating tool, you managed to make it easily accessible. Excellent flow, I was so impressed and did not want to miss out on anything (FOMO!), that I took the entire course 3x's!! Thanks you so much!

  • @abdelrahmanelkadi9343
    @abdelrahmanelkadi9343 8 หลายเดือนก่อน +5

    We need to continue these videos Chris, they really helped us out. Thank you.👏😄

  • @Horstlicious
    @Horstlicious ปีที่แล้ว +12

    Thanks a lot for your wireshark masterclass! Really great content, the exact right deepth and very well explained! Please consider to continue this series!

  • @sharpestasset9615
    @sharpestasset9615 2 ปีที่แล้ว +5

    I started studying for my ccna 3 weeks ago. 1 week in I found your channel and been watching you ever since. Great content. Not sure if it applies to my ccna but still love learning about TCP/IP. Much appreciated 👍

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Awesome! Go get that CCNA!

  • @billiraydray
    @billiraydray 2 ปีที่แล้ว +23

    Dear Chris I'm so happy I found you through David Bombal. You guys have really help me a lot in my studies. Thank you so much for providing all these very useful materials. Love from Sierra Leone❤️

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Great to have you here on the channel! Thank you for the comment and take care.

  • @lesliefernandes2980
    @lesliefernandes2980 ปีที่แล้ว +1

    Dear Chris - I just went through the quick 10 video's of your's on wireshark and I must say that you have taught me a lot in TCP packet analysis. Many thanks. Keep up the good work and GOD bless you.

  • @neiltropolis
    @neiltropolis 2 ปีที่แล้ว

    This did not work for me at first, so I shut down wireshark and restarted it. Works beautifully. Thank you very much.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Sorry to hear that. Can I ask where you got stuck? Did you unzip the files into a folder, then add the folder (not the files) to Wireshark? Latest version of Wireshark?

  • @CyberNancy
    @CyberNancy 2 ปีที่แล้ว +2

    I get a lot of questions about finding a computer’s location using the IP address. It seems the biggest challenges to locating a computer is NAT’ing and VPN usage.
    Thanks again for your great work.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Yes, exactly. But at least if we see some public IP's we can have an idea of where they are coming from. Thank you for the comment!

    • @zdrasbuytye
      @zdrasbuytye ปีที่แล้ว +1

      I was thinking the same. I usually used IP's from Europe and south America.

  • @RahuldeepSingh-ih5qj
    @RahuldeepSingh-ih5qj 2 ปีที่แล้ว

    Man, u r really oooosssmmmmmm. First things first your voice is really soothing, your way of expalaing concepts is great. U r covering topics that aren't even covered in expensive courses. Info tech field requires more people like u, informative, calm and great teacher

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Thanks for the feedback!!

  • @eksadiss
    @eksadiss 2 ปีที่แล้ว +1

    I just binged this whole series. Thank you so much

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Awesome! Glad you liked it!

  • @sammyfromsydney
    @sammyfromsydney 2 ปีที่แล้ว +1

    This series is great. Thank you very much for making it. Suggestion: Ideally you want a cheat cheat to go with each lesson for quick reference so you don't have to look through video when you forget where something is..

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      I like the idea! Thank you.

  • @mariap1571
    @mariap1571 ปีที่แล้ว

    I suppose real hackers would never use a server inside their city and country to perform attacks though...
    The cat is so nice) Thank you for your videos and kindness.

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว

      Yeah we first have to assume the IPs are either spoofed or proxied. But this can point us to some low-hanging fruit.

  • @termsservice9396
    @termsservice9396 5 หลายเดือนก่อน

    Thank you for this series, this will help me greatly in my cybersecurity goals.

  • @ohasis8331
    @ohasis8331 2 ปีที่แล้ว

    Wow! I stepped through your video and whilst my screen (Win 10, WS v 3.6) did not reflect what was showing on yours, a little tinkering on my part and blammo, there it was.
    Thankyou very much for the thorough explanation.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Nice! Glad it worked for you.

  • @user-qb3co2jb9z
    @user-qb3co2jb9z 2 ปีที่แล้ว +1

    Thank you, great content!!
    It is always nice when a cat comes to participate in the video 😇

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Trying to get him back onscreen soon. 😀

  • @ChitChat
    @ChitChat ปีที่แล้ว +3

    Unfortunately the tar.gz and csv formats are not working for me and the .mmdb implementation seems more involved than what appears in this video. I'm running windows 10.
    Update: If anyone else is having trouble like me just know that the tar.gz file has to be unzipped 2 times before you get to the .mmdb files.

    • @bigolboomerbelly4348
      @bigolboomerbelly4348 ปีที่แล้ว

      i am having that exact problem. please explain and I'll sub.

    • @ChitChat
      @ChitChat ปีที่แล้ว +1

      @@bigolboomerbelly4348 unzip once, then a second time. Then you will see the .mmdb files.

    • @juansanmiguel7139
      @juansanmiguel7139 ปีที่แล้ว

      Windows 10 also. I downloaded GZIP EDITION ID: GeoLite-ASN but it doesn’t give me the option to unzip, saved them to a local folder I named “wireshark stuff” not sure if that matters, please help ! Ps brand new to wireshark & all this computer stuff

  • @sekharsingh3969
    @sekharsingh3969 2 ปีที่แล้ว +1

    This video helped me to complete my assignment. Thanks man

  • @colinrogers9927
    @colinrogers9927 ปีที่แล้ว

    This is awesome. I use wireshark every day and did not know about this. Too cool. Thanks for sharing!

  • @Spirit25832
    @Spirit25832 2 ปีที่แล้ว +1

    Hey Chris, can u make a videos how to include the country clumn?

  • @denza2843
    @denza2843 ปีที่แล้ว

    I didn't get an email from maxmind, and i couldnt folow , but I watched the masterclass tutorial to the end

  • @cyrustheplayer
    @cyrustheplayer ปีที่แล้ว +5

    I performed all the steps. but Geo Ip doesnt appear in Endpoint

  • @Kafeiklys
    @Kafeiklys 2 ปีที่แล้ว

    Amazing!! This really help give all this data a better understanding for novices like me on wireshark capturing.

  • @nilmega
    @nilmega 2 ปีที่แล้ว

    Hi Chris, great content. Please don't stop posting this kind of content. Not sure why my setup did not work also I followed the instructions but had no luck.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +2

      Thanks for the comment. Hmmm… upgrade Wireshark? Restart it? Make sure you point Wireshark to the folder with the mmdb files, not to the files themselves.

  • @markpartridge9046
    @markpartridge9046 2 ปีที่แล้ว +2

    These are great tutorials thanks for your time and effort.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad you like them!

  • @vyasG
    @vyasG 2 ปีที่แล้ว

    Very Useful feature and it is easy to set up! Thank You for showing us how to set this up.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Glad it was helpful!

  • @peachycaper
    @peachycaper 2 ปีที่แล้ว +2

    This is an awesome feature, thanks for sharing!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      It really is! I use it quite a bit.

  • @CorpusCrispy
    @CorpusCrispy 2 หลายเดือนก่อน

    Thank you for the content, and for letting kitty participate!

  • @vivekchamoli7161
    @vivekchamoli7161 ปีที่แล้ว +4

    Hi Chris , thank you for the informative tutorial ..I tried to use the geo location feature but it seems country and location tab removed from endpoint section in version above 3.6.8 above as it shows RX , TX packets/byes only tried in windows and Linux same result.

    • @bigolboomerbelly4348
      @bigolboomerbelly4348 ปีที่แล้ว

      for me the city/country tabs showed up no lat/long and no data!

  • @Frank_Obinna
    @Frank_Obinna 6 หลายเดือนก่อน

    Hello Chris, I really appreciate all your classes. I actually tried doing it your way this time using Maxmind exactly the same way that you did to get those ip location but I didn't find any, pls what could be the reason.

  • @yapsejaiteh7
    @yapsejaiteh7 2 ปีที่แล้ว

    Thank you very much proffessor Chris. This is a great toturial for us

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad you liked it!

  • @dirkl9652
    @dirkl9652 2 ปีที่แล้ว

    Thanks for the tips. It works well for me on Windows PC with WS 3.6.1

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Thanks for the comment!

  • @marwit2928
    @marwit2928 6 หลายเดือนก่อน

    We love the cat!

  • @ratnavodutta
    @ratnavodutta 2 ปีที่แล้ว

    thank you @Chirs Geer for the Wireshark masterclass sessions. Your content is great. I will look forward to future session with latency in TCP and jitter in UDP. I love your cat :) seems like (he/she) wanted some "shark"fish for snacks :D

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Awesome, thank you!

  • @incredibledews66
    @incredibledews66 18 วันที่ผ่านมา

    which is good, downloading Geolite files in binary format or in CSV format?

  • @kevinaltizer
    @kevinaltizer 2 ปีที่แล้ว

    Nice feature in Wireshark! Thanks for sharing with us!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      thanks for the comment!

  • @danpacheco1
    @danpacheco1 2 ปีที่แล้ว

    That’s pretty cool. Also, the cat is a nice touch.

  • @RuFi0000000
    @RuFi0000000 2 ปีที่แล้ว

    The geo files were SHA256 and GZIP. I had no clue what to do with them on a Windows device or how to extract files like that.

  • @x0rZ15t
    @x0rZ15t 2 ปีที่แล้ว

    Yet again a fantastic video!!!
    Thank you for sharing the knowledge!

  • @thotakrishna262
    @thotakrishna262 11 หลายเดือนก่อน

    Sir i have learnt the best advice from you..but i wish to know exact location with the IP address so How do i find out the details so please you can take any video on this issue ..
    I hopefully you can give the reply to my message

  • @universalponcho
    @universalponcho 2 ปีที่แล้ว

    Thank you! Once again another very useful and awesome tutorial.

  • @raffihindoian6537
    @raffihindoian6537 ปีที่แล้ว

    Thanks, that was awesome. Very clear. Got it setup and working :) Think this will be useful.

  • @da_cat
    @da_cat 2 ปีที่แล้ว

    3:52 cat is like : this guy crazy again, talking to objects ... need to sit with him and make sure he does not harm himself 😾

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      I think you're right - my cat was like "He's gone crazy!"

    • @da_cat
      @da_cat 2 ปีที่แล้ว

      @@ChrisGreer Awesome tuts man, went from 0 to feeling like a little expert, def gonna watch the 1h ones also

  • @91thewatcher23
    @91thewatcher23 6 หลายเดือนก่อน

    Is Maxmind just taking this data from the WHOIS record for the IP registry?

  • @yeayea8334
    @yeayea8334 6 หลายเดือนก่อน

    Hi Chris, I just followed all steps but Whireshark is not allowed to open the files: when I click plus so add so point to that folder, Wireshark don’t see them, they are grey.
    Why?
    I have a macbook

  • @anonraxor317
    @anonraxor317 ปีที่แล้ว

    while i'm opening the map it shows blank page only.
    i'm using linux system.
    i've configured databases too..

  • @lferrerorocherx204
    @lferrerorocherx204 ปีที่แล้ว

    it actually works! thankyou, but after using it for a couple of days i tried the same procedure.. but instead showing the map after clicking on 'open in browser' it opens a notepad, how do i fix this ?

  • @pinkreefinformatica1372
    @pinkreefinformatica1372 2 ปีที่แล้ว

    Subscribed 'just' for the cat,,, he is just like mine,,, very interested in databases,,, ;-) an the food I gave him to let me work ;-))

  • @alimoammeri9483
    @alimoammeri9483 2 ปีที่แล้ว

    Nice tip, Thank you. I'm going to try it right now.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Awesome! let us know how it worked.

  • @latenttalent4523
    @latenttalent4523 9 หลายเดือนก่อน

    I did the same process like you but it is not working, can anyone help me to resolve this problem.

  • @socat9311
    @socat9311 2 ปีที่แล้ว

    This is useful for cases where you get a call that starts like "hello sir this is jon peters from microsoft"

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Haha... totally.

  • @user-gv9gj3hk3q
    @user-gv9gj3hk3q 4 หลายเดือนก่อน

    is it necessary to download geolite in order to find the location of IP address?

  • @Cloudconsultancy
    @Cloudconsultancy 4 หลายเดือนก่อน

    Thanks lot. for this Knowledge

  • @xldomlx4802
    @xldomlx4802 7 หลายเดือนก่อน

    im not sure what files to download on maxmind, ive downloaded some zips but they dont seem to be workinbg, d i need to open the,

  • @ivegyattocomment
    @ivegyattocomment 11 หลายเดือนก่อน

    when i download the database? which type do i choose? CSV??

  • @darktkm4422
    @darktkm4422 2 ปีที่แล้ว

    dear Chris your viedo is very usefull for me .. but I need how to export this ipmap.html file using TSHARK cmd .. not in GUI mode ..pls tell me ..

  • @nosystemissaf3
    @nosystemissaf3 ปีที่แล้ว

    the map feature is not working in my wireshark maybe version issue or something else i am using wireshark 4.0.3 and maxmind database is working fine but map is not working after clicking show in browser any one knows about this

  • @HalfInsaneOutdoorGuy
    @HalfInsaneOutdoorGuy ปีที่แล้ว

    Will you do more of these wireshark classes? say an advanced troubleshooting for pissy clients blaming the storage solution for their garbage network, vpn, or whatever? =D

  • @jony9867
    @jony9867 7 หลายเดือนก่อน

    Hi Chris, I have a problem with the map that can be exported from the endpoint statistics. I have Ubuntu as OS and Wireshark always runs there with root rights. The exported ipmap.html file is then also stored as root user and group. Therefore, I cannot open the file with my Chrome browser. I have already tried to change the user and group of the ipmap.html to my default user, which worked and I can now open the file, but I only see a white background without a map.
    The map cannot be opened directly from Wireshark either.
    Do you or anyone else know what to do?

  • @majiddehbi9186
    @majiddehbi9186 2 ปีที่แล้ว

    Hi Chris first happy New year sir, realy i was about to ask u this u are Just a GOd gift sir thx

  • @geisterhauz4287
    @geisterhauz4287 2 ปีที่แล้ว

    Is there away to narrow the search even further say to a physical address? ie coffee shop or home address?

  • @ericwf1
    @ericwf1 2 ปีที่แล้ว

    Wow, that's really cool!! Thanks Chris!!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad you liked it!

  • @nakotaapache4674
    @nakotaapache4674 11 หลายเดือนก่อน

    great stuff and tool

  • @limitless-codes
    @limitless-codes 4 หลายเดือนก่อน

    Great stuff.

  • @relaxation411
    @relaxation411 3 หลายเดือนก่อน

    Hey Chris. Thanks for this amazing lessons. I just want to quickly ask, Does VPN hide the real address from Wireshark mapping for the Geolocation?

    • @ChrisGreer
      @ChrisGreer  3 หลายเดือนก่อน +1

      It depends on where the capture is taken. Outside or inside tunnel?

    • @relaxation411
      @relaxation411 3 หลายเดือนก่อน

      @@ChrisGreer Thank you Chris

  • @bendono
    @bendono 2 ปีที่แล้ว

    Cool feature. I wasn't aware of it before. Next time please introduce your cat😼

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      I will! I put his name in the description, but I will do a proper intro next time. 😀

  • @tmps424
    @tmps424 8 หลายเดือนก่อน

    if they're using a vpn we're taking the vpn's ip or the persons's ip?

  • @gultekinbutun7910
    @gultekinbutun7910 2 ปีที่แล้ว

    Thanks a lot for sharing this great information.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad it was helpful!

  • @salmaabo-zaid3604
    @salmaabo-zaid3604 8 หลายเดือนก่อน

    Thank you very much

  • @user-pm3ll6dl9i
    @user-pm3ll6dl9i 11 หลายเดือนก่อน

    mine map button is faded , how to resolve it?

  • @Network-Mike
    @Network-Mike 2 ปีที่แล้ว

    Great tutorial, thanks!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad it was helpful!

  • @ruyerttt
    @ruyerttt 7 หลายเดือนก่อน

    Hello, thank you for posting those videos! But I have a question regarding geoip. Is there any tool or method to identify top 3 source ip countries in wireshark?

    • @ChrisGreer
      @ChrisGreer  7 หลายเดือนก่อน +1

      Yes! Statistics - Endpoints - sort on bytes to get top talkers. Look at top three country codes.

    • @ruyerttt
      @ruyerttt 7 หลายเดือนก่อน

      @@ChrisGreer Thank you so much!

    • @ruyerttt
      @ruyerttt 7 หลายเดือนก่อน

      @@ChrisGreer What if there are single packets from different ips being sent? how to identify the top countries then?

    • @ChrisGreer
      @ChrisGreer  7 หลายเดือนก่อน +1

      I would use tshark to do that. Read the file in, show the unique country codes and the number of incidents per code. Sort column, top three are your answer. Here is a video of generally how to do this - you would just need to export the GeoIP country code instead of the User Agent as shown in the video. th-cam.com/users/shortsT-PaBudIrUI?feature=shared

  • @MrRobot222
    @MrRobot222 2 ปีที่แล้ว

    Nice feature, thanks!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thanks for the comment Alex.

  • @sabitkondakc9147
    @sabitkondakc9147 2 ปีที่แล้ว

    Simply great, thanks a million.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      You bet - thank you for the comment.

  • @SuperAmir64
    @SuperAmir64 2 ปีที่แล้ว

    Hi Chris, i'm using ubuntu 22.04 but it's not working! do you have any updates about that?
    Thank you anyway for introducing cool stuffs.

  • @SafuraZaiba
    @SafuraZaiba 7 หลายเดือนก่อน

    Hi Chris...The geo location thing is not working for me. I extracted the zip files and placed the three files in a single folder. The file type shows "MMDB File" however in your video your file type was "Document". DOes that make any difference? else why is the source GeoIP missing in my feed? My Wireshark Version 4.2.1 (v4.2.1-0-gcfe37f471da9).

  • @jamesa4958
    @jamesa4958 2 ปีที่แล้ว

    Really awesome! Thanks

  • @pimscheffers
    @pimscheffers 2 ปีที่แล้ว

    Hey Chris, love your videos keep up the good work.
    I see you have some great custom wireshark profiles
    Could you share all your wireshark profiles with us so we can download them?

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Hello Pim, sure! I am working to get them posted on my website. I'll get them out to you guys soon!

    • @jfiffick
      @jfiffick 2 ปีที่แล้ว

      Funny. If you watched his other videos, he says he never gives his capture filters out. Need to customize to your preference on troubleshooting.

  • @suwoo2223
    @suwoo2223 ปีที่แล้ว

    much thanks

  • @SpookiePower
    @SpookiePower 2 ปีที่แล้ว

    Thanks :) Another useful video :)

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Thanks for the comment @BlueSpaceship

  • @marlyin666
    @marlyin666 9 หลายเดือนก่อน

    i live in syria i cant make account on maxmind bcs its banned here what i can do and thank you

  • @S2eedGH
    @S2eedGH 2 ปีที่แล้ว

    I don't know why the Wireshark crashed when I click on (three dots ...) in Max Mind Database Path, I'm facing this issue for a months now also I tried to uninstall and download new one, but same issue

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Hey Saeed, I see that when I touch the three dots two, ever since I upgraded to a Mac M1. I had to manually put the folder path in the bar instead of using the three dots. That made it work.

  • @chrismunyau4503
    @chrismunyau4503 11 หลายเดือนก่อน

    Which version of Wireshark is this?

  • @digisollabs1967
    @digisollabs1967 10 หลายเดือนก่อน

    Hi Chris ... really appreciate you sharing knowledge like this. This is awesome! I just have one question ... the Map does not seem to be displaying on any of my browsers. I tried to view it two ways ... through the Wireshark Endpoint window by clicking "Map --> Open in Browser" and by "Save As ...". Either of those files created, I changed the permissions from 600 to 666 and still did not display. Any suggestions? Again, thank you for doing what you are doing ... 🙂

    • @digisollabs1967
      @digisollabs1967 10 หลายเดือนก่อน

      Nevermind ... it seems to be a Debian/Kali issue ... corrected it with ... sudo apt install libjs-leaflet libjs-leaflet.markercluster ... again, thank you for sharing your knowledge!

  • @user-ey7qz1xf6d
    @user-ey7qz1xf6d 2 ปีที่แล้ว

    Chris, hi. Maybe I'm wrong but seems like it's not Moscow but Saint petersburg. The DC Selectel mentioned in the video is located in Petersburg and a traceroute to the IP proves it. The last and penultimate hops belong to Saint petersburg. Maybe GeoIP puts Moscow because of IP PI block's provider located in Moscow? If that is correct how can we believe that an attack comes from A and not B? Thanks for your videos

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Yeah you could be right. One of the reasons why I mentioned in the video that we have to take the location with a grain of salt... It's just what the database says. Before being absolutely sure I would definitely do more research on a given IP for location and other company data. And then... IP's can always be spoofed, which would make GeoIP irrelevant.

    • @user-ey7qz1xf6d
      @user-ey7qz1xf6d 2 ปีที่แล้ว +1

      @@ChrisGreer Exactly! There is no magic wand as always;) Thanks for your time!

  • @lukespencer5665
    @lukespencer5665 ปีที่แล้ว

    Your cats cute

  • @johnvardy9559
    @johnvardy9559 ปีที่แล้ว

    yeah but when someone used vpn you take the wrong geoip?

  • @tiville421
    @tiville421 2 ปีที่แล้ว

    It didnt work for me. I download the same format and it never populated. Not sure why.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      I'm looking into why this isn't working on Windows all of a sudden. I'll post when I figure it out. Thanks for letting me know.

  • @matthewcarlson9449
    @matthewcarlson9449 2 ปีที่แล้ว

    it wouldn't let me make an account because i dont have a company or can i just type anything in company name box even if i dont have a company im right now a student trying to gain skills and education to get my foot in the door in the cyber security field

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      You probably could put your school name in the company field.

  • @KevinCrabb
    @KevinCrabb 2 ปีที่แล้ว +1

    Hi, Chris, I'm having a hard time making it work on my Windows version of Wireshark. I downloaded it for MMDB but it was formatted in tar.gz not .mmdb. So I formatted it to .mmdb, point it to my path folder, restarted Wireshark but no luck. Is there something I missing?

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +2

      Hi Kevin - hmm.. I think it has to do with the way it was unzipped. Go ahead and reach out to me at packetpioneer (at) gmail.com and we will try it with an unzipped mmdb that works on my end.

    • @umaimaasghar5198
      @umaimaasghar5198 2 ปีที่แล้ว +1

      @@ChrisGreer Hi Chris! Unfortunately, I have also run into the same problem. Is there a way to resolve this? Would appreciate the help

    • @scottspa74
      @scottspa74 2 ปีที่แล้ว +1

      I'm having the same issue. All the DL links are for tar files. It made me think I'm looking in the wrong place. Anybody get this figured out?

  • @puttenicole
    @puttenicole 2 ปีที่แล้ว

    Cool stuff!

  • @Hartley94
    @Hartley94 2 ปีที่แล้ว

    Thank you

  • @faran4536
    @faran4536 2 ปีที่แล้ว

    First video of the new year

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      sure is! Buckle up for a whole lot more in 2022.

  • @cybersociedadebrasil101
    @cybersociedadebrasil101 2 ปีที่แล้ว

    very good

  • @no-de3lg
    @no-de3lg 2 ปีที่แล้ว

    Can I determine the scammer location

  • @anthonyaubuchon4260
    @anthonyaubuchon4260 ปีที่แล้ว

    Hello Chris, fantastic content. I just found your TH-cam channel and am going through most of your videos trying to learn a lot about wireshark. I ran into a problem trying to figure out how to get everything to show up here. I downloaded the 3 items from Maxmind. The GeoLite2 Country, City, and ASN databases and mapped them in the maxmind database directories tab under preferences and name resolution. They are all in one file location on my desktop. However i cannot get any of the information to show up in either the IP drop down or the statistics - endpoint window. Do you have an idea on what i could have done wrong? maybe i downloaded the wrong file formats? i am running windows 11 and have wireshark V4.0.4. I see the Map button however, it is greyed out i believe due to no country, city, or asn's showing up in the end point screen.

    • @aidamaja8712
      @aidamaja8712 ปีที่แล้ว

      Hello, I have the same issue, running Wireshark on windows 10.

    • @user-in5gm4xt7e
      @user-in5gm4xt7e ปีที่แล้ว

      @@aidamaja8712 did you manage to solve this problem?

    • @user-in5gm4xt7e
      @user-in5gm4xt7e ปีที่แล้ว

      did you manage to solve this problem?

    • @jermdoe123
      @jermdoe123 ปีที่แล้ว

      @@user-in5gm4xt7e I am having the same problem

    • @Dubergomezfonseca
      @Dubergomezfonseca 9 หลายเดือนก่อน

      Hi guys, I am also having the same issue, I am running it in Windows 11 home edition. But, I noticed that Criss uased the 2021 version and I downloaded the 2023 version of these databases. I am not sure if that is part of the problem.

  • @JohnMandersonBM
    @JohnMandersonBM ปีที่แล้ว

    Hey Chris, the maps button/layout has moved or gone. Does it existing on latest mac editions now?

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว

      Yeah they moved it to the left column on 4.0 and newer.

    • @JohnMandersonBM
      @JohnMandersonBM ปีที่แล้ว

      @@ChrisGreer Can't see a way to enable it. My windows box has it enabled

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว +2

      @@JohnMandersonBM Make sure you are on Statistics | Endpoints - Then make sure you have the IP button on top selected. You should see the Map button on the left activate.

  • @homayounshokri5041
    @homayounshokri5041 2 ปีที่แล้ว

    👍👍👍👍👍
    Graet

  • @prasadshinde8271
    @prasadshinde8271 2 ปีที่แล้ว

    I followed the process (download the Gzip file - extract - pointed the folder in Wireshark) but still, it's not working for me 😐

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Hmm.... reboot wireshark? after that, reboot system? (I HATE that as a solution but sometimes we need to kick Wireshark to see the folder and use the DB.

    • @prasadshinde8271
      @prasadshinde8271 2 ปีที่แล้ว

      @@ChrisGreer Still no luck.🙄

    • @KevinCrabb
      @KevinCrabb 2 ปีที่แล้ว

      @@prasadshinde8271 Me too. Do you have the Windows version of Wireshark?

    • @prasadshinde8271
      @prasadshinde8271 2 ปีที่แล้ว

      @@KevinCrabb Yes

  • @VitaminVS
    @VitaminVS 2 ปีที่แล้ว

    The cat was distracting :D

  • @willemdeswardt5684
    @willemdeswardt5684 ปีที่แล้ว

    What if the person spoof his ip?

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว

      Then it will show up in the location of where the spoofed IP is registered. So like we said in the video, it's a feature you kinda have to take with a grain of salt.