Sort by: Name Size Date
RSS FeediTunes
  • ARP Poisoning (t)
    Trace file - ARP poisoning process - map it out. Referenced in the Hacked Hosts: Network Forensics course.

    Last modified:

    08/13/09 10:17 AM ET

    Size:

    1.59KB
    My Library ...
  • Best Time Setting for Troubleshooting - Wireshark Tip 9 (iv)
    When users complain about poor network performance, capture their traffic (from as close to their systems as possible so you get round trip time values from their perspective). Set the Time column value to show you from the end of one packet to the end of the next packet by selecting View > Time Display Format > Seconds Since Previously Displayed Packet. Now you can sort this column to see where there are large gaps in time in the trace file.

    Last modified:

    08/05/09 02:32 AM ET

    Duration:

    0:57

    Size:

    4.73MB
    My Library ...
  • Bot Infected Host Analysis (Laura Chappell) (iv)
    iPhone video: Laura opens a trace file from an infected host, identifying the evidence of the compromise and demonstrating how to create a butt ugly filter to spot unusual DNS responses.

    Last modified:

    08/05/09 02:43 AM ET

    Duration:

    14:57

    Size:

    65.64MB
    My Library ...
  • Bot-Infected Host Analysis (Laura Chappell) (v)
    Full-size video: Laura opens a trace file from an infected host, identifying the evidence of the compromise and demonstrating how to create a butt ugly color filter to spot unusual DNS responses.

    Last modified:

    08/05/09 02:48 AM ET

    Duration:

    14:57

    Size:

    51.09MB
    My Library ...
  • Butt Ugly Color Filters (Laura Chappell) (v)
    Video - full size: Laura demonstrates the creation and use of her butt ugly color filters to distinguish unusual network communications.

    Last modified:

    08/05/09 02:41 AM ET

    Duration:

    6:34

    Size:

    15.1MB
    My Library ...
  • CACE Wifi Pilot (Laura Chappell) (p)
    Ron Nutter (TechBytes) interviews Laura Chappell to learn more about the new CACE Wifi Pilot product. Laura explains the elements that make CACE Wifi Pilot a boon to WLAN integrators and support technicians.

    Last modified:

    11/05/10 04:36 PM ET

    Duration:

    6:19

    Size:

    2.9MB
    My Library ...
  • Chargen (t)
    Trace file - Character Generator (chargen) process. Referenced in the Hacked Hosts: Network Forensics course.

    Last modified:

    08/13/09 10:18 AM ET

    Size:

    5.03KB
    My Library ...
  • Collect and Store Evidence (Tom Quilty) (p)
    Ron Nutter (TechBytes) chats with Thomas Quilty, CEO of BD Consulting and Investigations, about first evidence collection procedures after a breach has occurred. Tom describes what to document during the collection process, maintaining a chain of custody and storing the evidence for potential use in Court. Thomas Quilty has over twenty five years experience in law enforcement, including ten years investigating Federal and State of California High Technology Crimes.

    Last modified:

    11/05/10 04:41 PM ET

    Duration:

    6:32

    Size:

    3MB
    My Library ...
  • Data Breaches (Tom Quilty) (p)
    Ron Nutter (TechBytes) chats with Thomas Quilty, CEO of BD Consulting and Investigations, about what to do when you have had (or think you have had) a data breach. Tom explains the need for a ‘breach plan’ to prepare for the dreaded day and how important full understanding of the network interconnections can save your hide someday. Thomas Quilty has over twenty five years experience in law enforcement, including ten years investigating Federal and State of California High Technology Crimes.

    Last modified:

    11/05/10 02:28 PM ET

    Duration:

    6:26

    Size:

    2.95MB
    My Library ...
  • Evidence - Bot-Infected Host (t)
    Trace file used in the Bot-Infected Host Analysis video. Check it out yourself.

    Last modified:

    08/06/09 01:48 PM ET

    Size:

    17.44KB
    My Library ...
  • Future of CACE Pilot (Gerald Combs) (p)
    Ron Nutter (TechBytes) talks with Gerald Combs about the development progress on CACE Pilot, the graphical and reporting tool that integrates with Wireshark.

    Last modified:

    11/05/10 04:31 PM ET

    Duration:

    3:32

    Size:

    1.62MB
    My Library ...
  • Getting Organized (Laura Stack) (p)
    Ron talks with Laura Stack, the Productivity Pro, about where to start in the process of getting organized. Knowing techies are overwhelmed everyday by network and user demands, Laura discusses when mobile devices are the best answer and when paper solutions are the right answer. Laura discusses her use of the PRODUCTIVE acronym (being Prepared, Reducing timewasters, becoming Organized, being Disciplined, removing Unease/stress, Concentrating, using your Time effectively, managing Information, reviving your Vitality, focusing on your Equilibrium). Learn more about Laura Stack at theproductivitypro.com.

    Last modified:

    11/05/10 04:19 PM ET

    Duration:

    5:57

    Size:

    2.73MB
    My Library ...
  • Hacked Host - Client Dying (t)
    Trace file - client boots and CPU hits 100% in just a few minutes. Referenced in the Hacked Hosts: Network Forensics course.

    Last modified:

    08/13/09 10:18 AM ET

    Size:

    111.32KB
    My Library ...
  • Hacked Host - Evil Program (t)
    Look for unusual traffic in this trace file to see what happened to this host. Referenced in the Hacked Hosts: Network Forensics course.

    Last modified:

    08/13/09 10:18 AM ET

    Size:

    131.04KB
    My Library ...
  • Hacked Host - Sick Client (t)
    Trace file - scans from this host alerted the admin that something was wrong. Referenced in the Hacked Hosts: Network Forensics course.

    Last modified:

    08/13/09 10:16 AM ET

    Size:

    17.44KB
    My Library ...
  • HTTP (http-aol.pcap) (t)
    (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) Trace file of a web browsing session to www.aol.com.

    Last modified:

    08/11/09 08:05 PM ET

    Size:

    201.53KB
    My Library ...
  • HTTP (http-checkitout.pcap) (t)
    (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) Trace file of a web browsing session including GET and POST.

    Last modified:

    08/11/09 08:05 PM ET

    Size:

    463.32KB
    My Library ...
  • HTTP (http-client-refuses.pcap) (t)
    (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) This client has more than one connection to a streaming video server, but nothing happens when they begin the stream viewing process. A quick review of the trace file indicates that the client rudely sends TCP RST packets [P28] [P29] to shut down the connections. The fault is at the client. Most likely a popup blocker process is getting in the way.

    Last modified:

    08/11/09 08:04 PM ET

    Size:

    13.75KB
    My Library ...
  • HTTP (http-espn.pcap) (t)
    (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) How ugly can it get? Check out the flow graph of this connection to www.espn.com.

    Last modified:

    08/11/09 08:11 PM ET

    Size:

    1.58MB
    My Library ...
  • HTTP (http-fault-post.pcap) (t)
    (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) Although this company has a nice feedback form online, when you fill out the form and click submit they rudely send an (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) HTTP error code 403 [P10] [P13]. Someone needs to let the webmaster know the form is broken!

    Last modified:

    08/11/09 08:11 PM ET

    Size:

    11.51KB
    My Library ...
  • HTTP (http-msn.pcap) (t)
    (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) Browsing to www.msn.com is more complicated than it seems. When reviewing this trace, consider running Statistics > HTTP > Requests (do not apply a filter) to see how many systems the client actually connects to.

    Last modified:

    08/11/09 08:11 PM ET

    Size:

    298.27KB
    My Library ...
  • HTTP (http-partial-content.pcap) (t)
    (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) HTTP allows us to retrieve partial content of a file loaded on a web server. For example, perhaps we just want to get the artist information for an MP3 file, but we don''t want to download the entire file yet. This trace depicts a user sending a partial content query as noted by the ''Range: bytes=x-y'' header field. Cool!

    Last modified:

    08/11/09 08:12 PM ET

    Size:

    1.89MB
    My Library ...
  • HTTP (http-post.pcap) (t)
    (Referenced in the Trace File Analysis Session 2 course at chappellseminars.com) This trace shows a McAfee update process (preceded by the "McAfee dance") and use of POST operations.

    Last modified:

    08/11/09 08:13 PM ET

    Size:

    25.76KB
    My Library ...
  • Internet Safety for Kids (Laura Chappell) (p)
    Ron Nutter (TechBytes) talks with Laura Chappell about the latest findings regarding Internet safety for kids. Laura dispells the myth that social media sites are key dangers of the ''''''''net.

    Last modified:

    11/05/10 04:59 PM ET

    Duration:

    10:59

    Size:

    5.03MB
    My Library ...
  • Metageek WiSpy Adapters (Laura Chappell) (p)
    TechBytes Podcast - Ron Nutter interviews Laura Chappell to learn more about spectrum analysis using Metageek WiSpy adapters and Chanalyzer software.

    Last modified:

    11/05/10 02:28 PM ET

    Duration:

    8:24

    Size:

    3.85MB
    My Library ...
  • Minimize Security Risks (Tom Quilty) (p)
    Ron Nutter (TechBytes) chats with Thomas Quilty, CEO of BD Consulting and Investigations, about looking objectively at the corporate network to determine where risks are greatest. Discussing the need for ‘outside talent’ to objectively perform due diligence, Ron and Tom talk about how important certain tasks are to maintain credibility with clients, investors and the public. Thomas Quilty has over twenty five years experience in law enforcement, including ten years investigating Federal and State of California High Technology Crimes.

    Last modified:

    11/05/10 04:31 PM ET

    Duration:

    5:33

    Size:

    2.54MB
    My Library ...
  • Multicast Video Stream (t)
    Trace file of a UDP-based multicast going through a queuing device. Look at the IO graph after changing the X axis to 0.01 to see the holds in the queue.

    Last modified:

    08/06/09 01:57 PM ET

    Size:

    2.28MB
    My Library ...
  • Nessus Scan (t)
    Trace file - Standard Nessus scan on a target. Referenced in the Hacked Hosts: Network Forensics course.

    Last modified:

    08/13/09 10:19 AM ET

    Size:

    177.21KB
    My Library ...
  • New Wireshark Features (Gerald Combs) (p)
    Ron Nutter (TechBytes) talks with Gerald Combs, creator of Wireshark (formerly Ethereal) and Director of Open Source Projects at CACE Technologies about feature requests and upcoming features such as 64-bit windows, better MAC OS X support, triggers and more. In addition, Gerald talks about how to request features and add your own by contributing code.

    Last modified:

    11/05/10 04:19 PM ET

    Duration:

    5:19

    Size:

    2.44MB
    My Library ...
  • Nmap and Zenmap (Laura Chappell) (p)
    Ron Nutter (TechBytes) talks with Laura about the features of Nmap and the newly-added Zenmap graphical element. Laura raves about the Nmap book written by Gordon Lyons (creator of Nmap).

    Last modified:

    11/05/10 01:49 PM ET

    Duration:

    6:16

    Size:

    2.87MB
    My Library ...
  • OS Fingerprinting (Kirk Thomas) (p)
    Ron Nutter (TechBytes) talks with Kirk Thomas, creator of NetScanTools Pro (www.netscantools.com), about how to perform OS fingerprinting to identify devices on the network. Kirk explains how NetScanTools uses various types of ICMP packets to perform OS fingerprinting on a network and the issues that firewalls cause when sending these packets to the target. ICMP packets include Echo Requests'', '' Address Mask Requests'', '' Information Requests and Timestamp Requests. Kirk also explains how WinPcap is used to bypass the firewall as well and how fingerprinting can help locate rogue devices on the network. Finally, Kirk explains how banners can give away the identity of a host. Ron reminds listeners that you must be careful before running these tools on the network.

    Last modified:

    11/05/10 03:39 PM ET

    Duration:

    5:09

    Size:

    4.73MB
    My Library ...
  • OS Fingerprinting (t)
    Trace file of an ICMP-based OS fingerprinting operation. Look for illegal ping packets (icmp.type==8 && !icmp.code==0).

    Last modified:

    08/06/09 01:50 PM ET

    Size:

    4.63KB
    My Library ...
  • Port Scan (t)
    Trace file of a port scan process - something you really never want to see on your network unless you are in charge of the process.

    Last modified:

    08/06/09 01:44 PM ET

    Size:

    3.31KB
    My Library ...
  • Prepare for a Data Breach (Tom Quilty) (p)
    Ron Nutter (TechBytes) chats with Thomas Quilty, CEO of BD Consulting and Investigations, about the importance of building strong relationships with legal representatives and law enforcement BEFORE a breach occurs. Tom explains the role of HTCIA (High Technology Crime Investigation Association) in preparation of a breach. Thomas Quilty has over twenty five years experience in law enforcement, including ten years investigating Federal and State of California High Technology Crimes.

    Last modified:

    11/05/10 04:35 PM ET

    Duration:

    6:08

    Size:

    2.81MB
    My Library ...
  • Private Investigator Experience and References (Cynthia Navarro) (p)
    Ron Nutter (TechBytes) talks with Cynthia Navarro, Principal of Finnigan''s Way (www.finnegans-way.com), a private investigation firm that deals with various types of cybercrime cases about defining what you want in your private investigator''s report and defining expectations up front when hiring the private investigator. Cynthia references elements such as time tracking, order of interviews, Court documents referenced and confidential informant interviews. In addition, Cynthia stresses the importance of signing an NDA at the first meeting with the investigator to protect corporate trade secrets and confidentiality.

    Last modified:

    11/05/10 02:28 PM ET

    Duration:

    5:40

    Size:

    2.6MB
    My Library ...
  • Realtime Blacklist Check (Laura Chappell) (iv)
    Video - iPhone: Laura got an eCard that prompted her to do some research on the sender. You''''ll see her use NetScanTools Pro to do a batch RBL (realtime black list) check on the sender, examine the response from Spamhaus and then analyze the method NetScanTools Pro used to perform this RBL check. Sign up for her newsletter at chappellseminars.com to get links to the trace file used in this video and the bot-infected host video. Enjoy!

    Last modified:

    08/05/09 02:40 AM ET

    Duration:

    5:16

    Size:

    28.07MB
    My Library ...
  • Realtime Blacklist Check (t)
    Trace file showing the realtime blacklist check process used by NetScanTools to research a company that sent Laura a greeting card via email.

    Last modified:

    08/06/09 01:55 PM ET

    Size:

    9.35KB
    My Library ...
  • Realtime Blacklists (Kirk Thomas) (p)
    Kirk Thomas, creator of NetScanTools Pro (www.netscantools.com), talks with Ron about how Real Time Blacklist (RBL) servers work and how companies get on the list (a very painful experience for an innocent company). Kirk explains how to customize the RBL server list in NetScanTools and how to enable/disable RBL servers. Ron and Kirk discuss how companies can mistakenly get onto blacklists and how to check to see if your company has been put on a blacklist and how to validate spam is coming from a blacklisted address.

    Last modified:

    11/05/10 04:36 PM ET

    Duration:

    5:41

    Size:

    2.6MB
    My Library ...
  • Risk Assesment (Tom Quilty) (p)
    Ron Nutter (TechBytes) chats with Thomas Quilty, CEO of BD Consulting and Investigations, about the ongoing process of risk assessment including building a full inventory of network elements and prioritizing potential target information. Risk assessment is not a one-time task and requires diligence and consistency in an ever-changing business environment. Thomas Quilty has over twenty five years experience in law enforcement, including ten years investigating Federal and State of California High Technology Crimes.

    Last modified:

    11/05/10 03:59 PM ET

    Duration:

    5:03

    Size:

    2.32MB
    My Library ...
  • Set Up GeoIP - Wireshark v1.2.x (Laura Chappell) (iv)
    Laura demonstrates how to set up and use Wireshark''s GeoIP feature to map IP addresses to their geographic location on a global map.

    Last modified:

    08/05/09 02:42 AM ET

    Duration:

    5:42

    Size:

    27.13MB
    My Library ...
  • Signs of a Compromised Host (Laura Chappell) (p)
    TechBytes Podcast - Ron Nutter interviews Laura to hear the types of traffic that make her skin crawl - from IRC sessions to unusual DNS responses and more.

    Last modified:

    11/05/10 04:31 PM ET

    Duration:

    6:56

    Size:

    3.18MB
    My Library ...
  • smb_protocol-request-reply
    See http://seclists.org/fulldisclosure/2009/Sep/0039.html. See chappellseminars.com/projects for details on catching unusual SMB Negotiate Protocol Request packets. (See also smb_protocol-request-reply.pcap) [Submitted by Laura Chappell, chappellu.com on 090809]

    Last modified:

    09/08/09 03:15 PM ET

    Size:

    498B
    My Library ...
  • smb_protocol-request-reply4filtertest
    See http://seclists.org/fulldisclosure/2009/Sep/0039.html. See chappellseminars.com/projects for details on catching unusual SMB Negotiate Protocol Request packets. (See also smb_protocol-request-reply.pcap) [Submitted by Laura Chappell, chappellu.com on 090809]

    Last modified:

    09/08/09 03:15 PM ET

    Size:

    1.41KB
    My Library ...
  • Sniffing FTP Passwords (Laura Chappell) (iv)
    iPhone video: Laura shows how to capture traffic and reassemble the TCP stream to easily see the FTP username and password in clear text.

    Last modified:

    08/06/09 02:14 AM ET

    Duration:

    4:29

    Size:

    14.07MB
    My Library ...
  • Switch Port Mapper (Kirk Thomas) (p)
    Ron Nutter (TechBytes) talks with Kirk Thomas, creator of NetScanTools Pro (www.netscantools.com) and Switch Port Mapper, about the port detail that Switch Port Mapper can perform discovery on and the information you can gather. Kirk then explains how Switch Port Mapper works with a variety of managed switches in the industry including HP, Cisco, Dell, NetGear, Nortel, DLink, 3Com, Linksys and more and gives some hints on mapping your network devices using SNMP read community strings. Finally, Kirk explains how Switch Port Mapper can be used on a regular basis and data can be exported for further analysis. The podcast closes with security warnings.

    Last modified:

    11/05/10 04:41 PM ET

    Duration:

    5:24

    Size:

    2.47MB
    My Library ...
  • Top Troubleshooting Tools - 2009 (Laura Chappell) (p)
    Ron Nutter (TechBytes) and Laura talk about their favorite troubleshooting tools.

    Last modified:

    11/05/10 04:27 PM ET

    Duration:

    7:36

    Size:

    3.48MB
    My Library ...
  • Tshark Interface Selection - Tip 8 (Laura Chappell) (iv)
    Tshark is the command-line capture tool that comes with Wireshark (look in the Wireshark program directory and consider adding this directory to your path so you can run Tshark from your trace file directory). Type tshark -D (must be a capital "D") to view the interface list. If you want to capture traffic on the third interface listed, you would use tshark -i 3 (the "i" parameter indicates the interface number you want to capture on).

    Last modified:

    08/05/09 02:45 AM ET

    Duration:

    2:29

    Size:

    6.72MB
    My Library ...
  • When a Breach Occurs (Tom Quilty) (p)
    Ron Nutter (TechBytes) chats with Thomas Quilty, CEO of BD Consulting and Investigations, about the fact that it is impossible to completely stop a breach from occurring. Tom reiterates the need for risk analysis and management and explains the difference between a disaster recovery plan and a breach plan. Your first reactions may be defined by legal requirements and this information should be known in advance to save face with investors, clients and the public. Who is going to be the leader during the reactive process after a breach? What about legal counsel and the directory of investigation/security management? What about the marketing director – do they have a roll in the reaction? The key here is to ‘stop the bleeding’ and begin resolving the problem. Thomas Quilty has over twenty five years experience in law enforcement, including ten years investigating Federal and State of California High Technology Crimes.

    Last modified:

    11/05/10 04:43 PM ET

    Duration:

    5:22

    Size:

    4.93MB
    My Library ...
  • When to Hire a PI (Cynthia Navarro) (p)
    Ron Nutter (TechBytes) talks with Cynthia Navarro, Principal of Finnigan''s Way (www.finnegans-way.com), a private investigation firm that deals with various types of cybercrime cases including intellectual property, unauthorized distribution, internal employee theft, corporate espionage, identity theft and more. Cynthia explains how to contact a private investigator and define the case before the hiring takes place.

    Last modified:

    11/05/10 04:43 PM ET

    Duration:

    5:48

    Size:

    2.66MB
    My Library ...
  • Wireshark and VMware (Gerald Combs) (p)
    Gerald Combs, creator of Wireshark (formerly Ethereal) and Director of Open Source Projects at CACE Technologies, talks with Ron about capturing traffic in a virtual environment, such as VMware Workstation'', '' Fusion and Server platforms. Not for the faint of heart'', '' Gerald explains the VMnet interface and issues in packet capture. Gerald introduces VMnet Sniffer or Vnet Sniffer utilities and warns of their limitations and how the OS affects the capture process.

    Last modified:

    11/05/10 04:31 PM ET

    Duration:

    4:41

    Size:

    2.15MB
    My Library ...
  • Wireshark and VMWare ESx (Gerald Combs) (p)
    Ron Nutter (TechBytes) talks with Gerald Combs, creator of Wireshark (formerly Ethereal) and Director of Open Source Projects at CACE Technologies, about capturing traffic in a virtual environment, such as VMware Workstation'', '' Fusion and Server platforms. Not for the faint of heart'', '' Gerald explains the VMnet interface and issues in packet capture. Gerald introduces VMnet Sniffer or Vnet Sniffer utilities and warns of their limitations and how the OS affects the capture process.

    Last modified:

    11/05/10 04:41 PM ET

    Duration:

    5:23

    Size:

    2.47MB
    My Library ...
  • Wireshark Jumpstart Seminars (Laura Chappell) (p)
    Ron Nutter (TechBytes) talks with Laura about the tremendously successful Jumpstart series launched in May 2009.

    Last modified:

    11/05/10 04:19 PM ET

    Duration:

    6:26

    Size:

    2.95MB
    My Library ...
  • WLAN PPI Header (t)
    Trace file of an 802.11 PPI header.

    Last modified:

    08/06/09 01:46 PM ET

    Size:

    420B
    My Library ...
  • WLAN Radiotap Header (t)
    Trace File of an 802.11 packet showing the Radiotap header.

    Last modified:

    08/06/09 01:46 PM ET

    Size:

    396B
    My Library ...
  • WLAN Traffic on a Plane (t)
    So much for "turn off the wireless feature" on those planes, eh? This trace was taken on a flight from LAX to SJC after the TechEd conference.

    Last modified:

    08/06/09 01:45 PM ET

    Size:

    9.42KB
    My Library ...
  • Xprobe OS Fingerprinting (t)
    Trace file - Xprobe2 running against a target. Referenced in the Hacked Hosts: Network Forensics course.

    Last modified:

    08/13/09 10:17 AM ET

    Size:

    1.21KB
    My Library ...

Your library is empty. Use the Upload Content button to add content.

Plays with Flash plugin
Plays with Windows Media Player plugin
Plays with Html5 player
Plays with Silverlight plugin
Camtasia Studio Presentation
Plays with QuickTime plugin
Image displays in browser
Plays with Real Media plugin
Click to View
Click to Open
Click to Edit
Click to Share
Click to Delete
Click to Delete Invitation