Wireshark Tutorial Series #2. Tips and tricks used by insiders and veterans

Поділитися
Вставка
  • Опубліковано 18 вер 2024
  • This session explains the dangers of using default settings without fully recognizing what's at play. Watch this short video and learn how default settings can interfere with HTTP analysis.

КОМЕНТАРІ • 12

  • @gungho1984
    @gungho1984 11 років тому

    Very clear description of Wireshark's “Allow subdissector to reassemble TCP streams” feature and how this can lead to some false assumptions. Cool.

  • @hansangb
    @hansangb  11 років тому

    Thanks for the heads up Larry. It's like the anti-hypertext example!

  • @ChrisGreer
    @ChrisGreer 10 років тому

    Nice summary Hansang. Thanks for posting.

  • @gungho1984
    @gungho1984 11 років тому +1

    By the way, I love to examine PKI certificates and found something pretty weird. I had turned off TCP reassembly and noticed I saw less certificates then when it is on. Upon further analysis this was because some newer certificates are using Elliptical Curve (ECDSA) keys and these are much smaller than RSA keys and fit in a single packet. To be able to display RSA certificates, I need to turn TCP reassembly back on.

  • @hansangb
    @hansangb  11 років тому

    Thank you Eric

  • @infestedkudzu
    @infestedkudzu 11 років тому

    Helped me. Thanks!

  • @seresos1
    @seresos1 10 років тому

    Really good

    • @hansangb
      @hansangb  10 років тому

      Thank you Erik.

  • @hansangb
    @hansangb  11 років тому

    Larry, infestedkudzu, Thank you!
    Larry, for some reason, your comment 'went underground' and I couldn't find it (to approve it). Weird.

  • @ericdavid890
    @ericdavid890 11 років тому

    Nice Werk!

  • @tonyrosam
    @tonyrosam 9 років тому

    Dude... I hope you do not make that many errors talking to IT on a phone!

  • @iwantcheesypuffs
    @iwantcheesypuffs 10 років тому

    Choosy mothers choose gif. Oh wait Jiff is peanut butter. Why is he talking about peanut butter?