Security Basics mailing list archives

Re: Packet trace analysis


From: Jon Schipp <jonschipp () gmail com>
Date: Wed, 22 Feb 2012 13:49:35 -0500

ipsumdump can give you various stats.

You might look at tcptrace, tcptrack, and even etherape (graphical).

On Wed, Feb 22, 2012 at 12:29 PM, Tippy Ahluwalia <tippya () pokerstars com> wrote:
Agreed with Bill, Ineed Wireshark will do this.

Tippy

----- Original Message -----
From: listbounce () securityfocus com <listbounce () securityfocus com>
To: 'cossettepatrick () gmail com' <cossettepatrick () gmail com>; security-basics () securityfocus com 
<security-basics () securityfocus com>
Sent: Wed Feb 22 17:09:01 2012
Subject: RE: Packet trace analysis

Wireshark will do this.

The following will work for version 1.6.2

Load the trace into wireshark.
Select the Statistics menu.
Click Endpoints.
In the box, turn off Name Resolution (the checkbox near the lower left corner).
For a list of all IP addresses choose the IPv4:# tab.  To sort by IP address click on the Address header.
To see a list of ports used by an address select the TCP or UDP tab.  You can sort on Address or Port in this window.

If you want to see conversations per IP address, Click on the Statistics menu.
Click Conversations.
Turn off Name Resolution.

Bill


-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of cossettepatrick () gmail 
com
Sent: Wednesday, February 22, 2012 6:41 AM
To: security-basics () securityfocus com
Subject: Packet trace analysis

Hi,

I'm looking for a tool that could give me stats on a pcap file. For instance, I would like a list of all unique IP 
addresses that were captured, as well as which source and destination ports were used by each of these addresses.

That is only one of the features that I would find useful in an analysis tool.

Does someone know of such a tool?

Thank you.

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: