Wireshark mailing list archives

Re: Anonymising PCAP files with Wireshark?


From: Kevin Cullimore <kcullimo () runbox com>
Date: Wed, 25 Jan 2012 18:24:37 -0500

On 1/25/2012 9:45 AM, Grégoire, André wrote:

Hi Everyone,

What is the best way to anonymize pcap files? Mainly substitute a real IP address and mac address for a fake one.

There seems to be a lot of scripts out there that change one or the other but I am looking if something is generally accepted as best practice or tried tested and true by this community.

As of Sharkfest 2011, that appeared to be a work-in-progress, but the emerging consensus regarding the scope of the problem included factors beyond header interface addresses.

Thanks for your time, it's appreciated.

Andre

________________________________

*Andre Gregoire*

Senior Enforcement Officer

Electronic Commerce Enforcement

Canadian Radio-television and Telecommunications Commission (CRTC)

andre.gregoire () crtc gc ca

Telephone 819-953-6972

Government of Canada



___________________________________________________________________________
Sent via:    Wireshark-users mailing list<wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
              mailto:wireshark-users-request () wireshark org?subject=unsubscribe

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: