Wireshark 101: Feedback and Tips - HakTip 141

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 มี.ค. 2016
  • Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:
    ____________________________________________
    -------------------------------
    Shop: www.hakshop.com
    Support: / threatwire
    Subscribe: / hak5
    Our Site: www.hak5.org
    Contact Us: / hak5
    ------------------------------
    Today on Haktip we're checking out your feedback and tips for Wireshark.
    Øyvind Nesland writes: I have a tip for how I've used Wireshark in my job as a network admin. We had a problem with IP-phones and our DHCP-server, and ended up with address-conflicts because two phones would use the same IP. To solve this and identify the phones, I used Wireshak and filtered on arp.duplicate-address-detected. This will give you all the duplicate addresses on your network, and helped me solve my problem.
    You can find all the other filters related to address resolution protocol at this link: www.wireshark.org/docs/dfref/...
    Michael writes: At one of our branch offices, users were having issues with Internet connectivity. Sometimes okay…most of the time horrible. After verifying cabling and then settings on the router and work stations, I used WireShark to see what was going on. Bingo! I found a rouge wireless router that was using it’s external IP address (which was on the office’s internal network) that conflicted with the office’s default gateway. The packet capture session showed the ARP transactions between different MAC addresses with the same IP. Found the rouge router and cut the Ethernet cable leading to the area it was located. Without a doubt, fixed the issue.
    Taylor asks: Does adding "Client FQDN" as a column mean a way to read names people offer out?
    Philippe writes: Hi Shannon,
    In wireshark's filter bar, the expression :"ip.dst != 192.168.1.1" can generate issues (that's why it's hilighted in yellow ). You may write something like : "not (ip.dst == 192.168.1.1)" or "!(ip.addr == bla.bla)" (appears then in green in the filter bar.) As said here : (sorry for the broken line) www.wireshark.org/docs/wsug_h... in section 6.4.4. A common mistake. Best regards, and tons of kisses from France to all the team.
    Crazy52: I found a page with some examples to connect to wireshark over SSH
    www.commandlinefu.com/commands... . I have a raspbarry pi with a lan tap monitoring my internet traffic over eth0 and a usb ethernet adapter connecting it back into my network. Using windows with putty + wireshark i managed to get it to work with a command line.
    ~-~~-~~~-~~-~
    Please watch: "Bash Bunny Primer - Hak5 2225"
    • Bash Bunny Primer - Ha...
    ~-~~-~~~-~~-~
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 10

  • @brieri418
    @brieri418 8 ปีที่แล้ว +1

    Shannon thank you for helping people with the multiple shows you do with Darren and Patrick. You and guys are awesome I would love to spend a week with you all I bet I would learn a lot

  • @jmeacha7
    @jmeacha7 8 ปีที่แล้ว

    I'm a networking adjunct professor and I use many of your videos in class to help explain things. Thanks for all you do!!!

  • @JohnSchmitt3rd
    @JohnSchmitt3rd 8 ปีที่แล้ว

    LOVE your hair Shannon!!

  • @devslashuser2884
    @devslashuser2884 8 ปีที่แล้ว +1

    you guys are amazing

  • @orochiokada
    @orochiokada 8 ปีที่แล้ว

    Cool glasses Shannon!

  • @KowboyUSA
    @KowboyUSA 8 ปีที่แล้ว

    I like Wiresharking.

  • @mankee2211
    @mankee2211 8 ปีที่แล้ว +1

    that sound sample in the background sounds like "coder girl"

  • @bilivigijhak
    @bilivigijhak 8 ปีที่แล้ว

    nice hair :) like the color

  • @devslashuser2884
    @devslashuser2884 8 ปีที่แล้ว

    first