SlideShare una empresa de Scribd logo
1 de 13
Capture file manipulation Part II : changing packets  September 2008
Welcome Back! ,[object Object],[object Object]
This months topic ,[object Object],[object Object],[object Object],[object Object],[object Object]
Why change the snap length ,[object Object],[object Object]
Change the snap length of packets $ $  editcap -s 68 test.cap tmp.cap $ $  tshark -c1 -r test.cap -V | grep "^Frame"   Frame 1 (110 bytes on wire,  110  bytes captured) $  tshark -c1 -r tmp.cap -V | grep "^Frame" Frame 1 (110 bytes on wire, 68 bytes captured) $ $  capinfos -csd test.cap  File name: test.cap Number of packets: 27  File size:  5740  bytes Data size:  5284  bytes $  capinfos -csd tmp.cap  File name: tmp.cap Number of packets: 27  File size:  2154  bytes Data size:  5284  bytes $
Useful snap length values ,[object Object],[object Object],[object Object],[object Object]
Why change timestamps of packets ,[object Object],[object Object]
Change the time by how much? ,[object Object],[object Object],[object Object],[object Object]
Which packets to use for syncing time ,[object Object],[object Object],[object Object],[object Object],[object Object]
Change the timestamps of packets $  tshark -ta -r client.cap "tcp.flags.syn==1" 1 22:31:59.246452 192.168.1.46 -> 192.168.1.20 TCP 43426 > http [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=1 2 22:31:59.248515 192.168.1.20 -> 192.168.1.46 TCP http > 43426 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460 WS=7 $  tshark -ta -r server.cap "tcp.flags.syn==1" 1 22:31:49.548529 192.168.1.46 -> 192.168.1.20 TCP 43426 > http [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=1 2 22:31:49.548556 192.168.1.20 -> 192.168.1.46 TCP http > 43426 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460 WS=7 $ correction  = (59.246452-49.548529 + 59.248515-49.548556)/2 =  9.698941 $  editcap -t 9.698941 server.cap server-corrected.cap $  tshark -ta -r server-corrected.cap "tcp.flags.syn==1" 1 22:31:59.247470 192.168.1.46 -> 192.168.1.20 TCP 43426 > http [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=1 2 22:31:59.247497 192.168.1.20 -> 192.168.1.46 TCP http > 43426 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460 WS=7 $
Change the file type of a capture file $ $  editcap -F netmon1 test.cap tmp.cap  $ $  capinfos -tsd *cap File name: test.cap File type:  Wireshark/tcpdump/... - libpcap File size: 5740 bytes Data size: 5284 bytes File name: tmp.cap File type:  Microsoft NetMon 1.x File size: 5736 bytes Data size: 5284 bytes $
That's all folks! ,[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object]

Más contenido relacionado

Destacado

Campamentos educativos. invitación 8 de abril 2013. taller volante salto
Campamentos educativos. invitación 8 de abril 2013. taller volante saltoCampamentos educativos. invitación 8 de abril 2013. taller volante salto
Campamentos educativos. invitación 8 de abril 2013. taller volante salto
Daniela María Zabala Filippini
 
Rueckennews wipp 12-2013
Rueckennews wipp 12-2013Rueckennews wipp 12-2013
Rueckennews wipp 12-2013
Peter Berger
 
Certificat de travail Oliver Vogt_27032016
Certificat de travail Oliver Vogt_27032016Certificat de travail Oliver Vogt_27032016
Certificat de travail Oliver Vogt_27032016
Oliver Vogt
 
3d Max Render 01 Raytrace Skylight
3d Max Render 01 Raytrace Skylight3d Max Render 01 Raytrace Skylight
3d Max Render 01 Raytrace Skylight
lab_digital
 
3-Uso básico de Kubuntu
3-Uso básico de Kubuntu3-Uso básico de Kubuntu
3-Uso básico de Kubuntu
Digna González
 
Análisis de posicionamiento
Análisis de posicionamientoAnálisis de posicionamiento
Análisis de posicionamiento
Moizez Morgan
 

Destacado (17)

Pressearbeit für Radreise-Veranstalter
Pressearbeit für Radreise-VeranstalterPressearbeit für Radreise-Veranstalter
Pressearbeit für Radreise-Veranstalter
 
Portafolio esteban rs.
Portafolio esteban rs.Portafolio esteban rs.
Portafolio esteban rs.
 
Campamentos educativos. invitación 8 de abril 2013. taller volante salto
Campamentos educativos. invitación 8 de abril 2013. taller volante saltoCampamentos educativos. invitación 8 de abril 2013. taller volante salto
Campamentos educativos. invitación 8 de abril 2013. taller volante salto
 
Rueckennews wipp 12-2013
Rueckennews wipp 12-2013Rueckennews wipp 12-2013
Rueckennews wipp 12-2013
 
Certificat de travail Oliver Vogt_27032016
Certificat de travail Oliver Vogt_27032016Certificat de travail Oliver Vogt_27032016
Certificat de travail Oliver Vogt_27032016
 
Tecnicas oprantes
Tecnicas oprantesTecnicas oprantes
Tecnicas oprantes
 
Vision sesion 15-okey
Vision sesion 15-okeyVision sesion 15-okey
Vision sesion 15-okey
 
Social Health: Emerging Media + Healthcare Marketing
Social Health: Emerging Media + Healthcare MarketingSocial Health: Emerging Media + Healthcare Marketing
Social Health: Emerging Media + Healthcare Marketing
 
04 ¿Qué hace una diosa egipcia bañándose en el río Turia en Valencia?
04 ¿Qué hace una diosa egipcia bañándose en el río Turia en Valencia?04 ¿Qué hace una diosa egipcia bañándose en el río Turia en Valencia?
04 ¿Qué hace una diosa egipcia bañándose en el río Turia en Valencia?
 
LAS MICROCOMPUTADORAS EN LA EDUCACIÓN BÁSICA DEL SISTEMA EDUCATIVO NACIONAL
LAS MICROCOMPUTADORAS EN LA EDUCACIÓN BÁSICA DEL SISTEMA EDUCATIVO NACIONALLAS MICROCOMPUTADORAS EN LA EDUCACIÓN BÁSICA DEL SISTEMA EDUCATIVO NACIONAL
LAS MICROCOMPUTADORAS EN LA EDUCACIÓN BÁSICA DEL SISTEMA EDUCATIVO NACIONAL
 
Manual performa
Manual performaManual performa
Manual performa
 
3d Max Render 01 Raytrace Skylight
3d Max Render 01 Raytrace Skylight3d Max Render 01 Raytrace Skylight
3d Max Render 01 Raytrace Skylight
 
3-Uso básico de Kubuntu
3-Uso básico de Kubuntu3-Uso básico de Kubuntu
3-Uso básico de Kubuntu
 
Análisis de posicionamiento
Análisis de posicionamientoAnálisis de posicionamiento
Análisis de posicionamiento
 
IES 5 - Practical Experience
IES 5 - Practical ExperienceIES 5 - Practical Experience
IES 5 - Practical Experience
 
Bharti Airtel
Bharti AirtelBharti Airtel
Bharti Airtel
 
Patologías infecciosas, la nueva vacuna contra la Tuberculosis. Carlos Martín
Patologías infecciosas, la nueva vacuna contra la Tuberculosis. Carlos MartínPatologías infecciosas, la nueva vacuna contra la Tuberculosis. Carlos Martín
Patologías infecciosas, la nueva vacuna contra la Tuberculosis. Carlos Martín
 

Más de Denny K

Más de Denny K (20)

5:7:2024 - Fourth Noble Truth • Mindfulness Meditation and Dharma Talk with V...
5:7:2024 - Fourth Noble Truth • Mindfulness Meditation and Dharma Talk with V...5:7:2024 - Fourth Noble Truth • Mindfulness Meditation and Dharma Talk with V...
5:7:2024 - Fourth Noble Truth • Mindfulness Meditation and Dharma Talk with V...
 
4/30/2024「同心共善」善心法師網上禪修班 (粵語) ..........
4/30/2024「同心共善」善心法師網上禪修班 (粵語) ..........4/30/2024「同心共善」善心法師網上禪修班 (粵語) ..........
4/30/2024「同心共善」善心法師網上禪修班 (粵語) ..........
 
4/23/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
4/23/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..4/23/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
4/23/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
4/16/2024「同心共善」善心法師網上禪修班 (粵語) ..........
4/16/2024「同心共善」善心法師網上禪修班 (粵語) ..........4/16/2024「同心共善」善心法師網上禪修班 (粵語) ..........
4/16/2024「同心共善」善心法師網上禪修班 (粵語) ..........
 
4/2/2024 - Fourth Noble Truth • Mindfulness Meditation and Dharma Talk with V...
4/2/2024 - Fourth Noble Truth • Mindfulness Meditation and Dharma Talk with V...4/2/2024 - Fourth Noble Truth • Mindfulness Meditation and Dharma Talk with V...
4/2/2024 - Fourth Noble Truth • Mindfulness Meditation and Dharma Talk with V...
 
3/26/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
3/26/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..3/26/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
3/26/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
3/19/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
3/19/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..3/19/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
3/19/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
3/12/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
3/12/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..3/12/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
3/12/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
3:5:2024 - Third Noble Truth • Mindfulness Meditation and Dharma Talk with Ve...
3:5:2024 - Third Noble Truth • Mindfulness Meditation and Dharma Talk with Ve...3:5:2024 - Third Noble Truth • Mindfulness Meditation and Dharma Talk with Ve...
3:5:2024 - Third Noble Truth • Mindfulness Meditation and Dharma Talk with Ve...
 
2/27/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
2/27/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..2/27/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
2/27/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
2/20/2024「同心共善」善心法師網上禪修班 (粵語) ..........
2/20/2024「同心共善」善心法師網上禪修班 (粵語) ..........2/20/2024「同心共善」善心法師網上禪修班 (粵語) ..........
2/20/2024「同心共善」善心法師網上禪修班 (粵語) ..........
 
2/13/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
2/13/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..2/13/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
2/13/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
2/6/2023 - Second Noble Truth • Mindfulness Meditation and Dharma Talk with V...
2/6/2023 - Second Noble Truth • Mindfulness Meditation and Dharma Talk with V...2/6/2023 - Second Noble Truth • Mindfulness Meditation and Dharma Talk with V...
2/6/2023 - Second Noble Truth • Mindfulness Meditation and Dharma Talk with V...
 
1/30/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
1/30/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..1/30/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
1/30/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
1/23/2024「同心共善」善心法師網上禪修班 (粵語) ..........
1/23/2024「同心共善」善心法師網上禪修班 (粵語) ..........1/23/2024「同心共善」善心法師網上禪修班 (粵語) ..........
1/23/2024「同心共善」善心法師網上禪修班 (粵語) ..........
 
1/16/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
1/16/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..1/16/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
1/16/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
1/9/2024「同心共善」善心法師網上禪修班 (粵語) ………………………..
1/9/2024「同心共善」善心法師網上禪修班 (粵語) ………………………..1/9/2024「同心共善」善心法師網上禪修班 (粵語) ………………………..
1/9/2024「同心共善」善心法師網上禪修班 (粵語) ………………………..
 
1/2/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
1/2/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong1/2/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
1/2/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
 
12/27/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
12/27/2023「同心共善」善心法師網上禪修班 (粵語) …………………..12/27/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
12/27/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
 
12/20/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
12/20/2023「同心共善」善心法師網上禪修班 (粵語) …………………..12/20/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
12/20/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
 

Último

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Último (20)

Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 

OSTU - Sake Blok on Wireshark Capture File Manipulation (Part II)

  • 1. Capture file manipulation Part II : changing packets September 2008
  • 2.
  • 3.
  • 4.
  • 5. Change the snap length of packets $ $ editcap -s 68 test.cap tmp.cap $ $ tshark -c1 -r test.cap -V | grep "^Frame" Frame 1 (110 bytes on wire, 110 bytes captured) $ tshark -c1 -r tmp.cap -V | grep "^Frame" Frame 1 (110 bytes on wire, 68 bytes captured) $ $ capinfos -csd test.cap File name: test.cap Number of packets: 27 File size: 5740 bytes Data size: 5284 bytes $ capinfos -csd tmp.cap File name: tmp.cap Number of packets: 27 File size: 2154 bytes Data size: 5284 bytes $
  • 6.
  • 7.
  • 8.
  • 9.
  • 10. Change the timestamps of packets $ tshark -ta -r client.cap "tcp.flags.syn==1" 1 22:31:59.246452 192.168.1.46 -> 192.168.1.20 TCP 43426 > http [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=1 2 22:31:59.248515 192.168.1.20 -> 192.168.1.46 TCP http > 43426 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460 WS=7 $ tshark -ta -r server.cap "tcp.flags.syn==1" 1 22:31:49.548529 192.168.1.46 -> 192.168.1.20 TCP 43426 > http [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=1 2 22:31:49.548556 192.168.1.20 -> 192.168.1.46 TCP http > 43426 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460 WS=7 $ correction = (59.246452-49.548529 + 59.248515-49.548556)/2 = 9.698941 $ editcap -t 9.698941 server.cap server-corrected.cap $ tshark -ta -r server-corrected.cap "tcp.flags.syn==1" 1 22:31:59.247470 192.168.1.46 -> 192.168.1.20 TCP 43426 > http [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=1 2 22:31:59.247497 192.168.1.20 -> 192.168.1.46 TCP http > 43426 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460 WS=7 $
  • 11. Change the file type of a capture file $ $ editcap -F netmon1 test.cap tmp.cap $ $ capinfos -tsd *cap File name: test.cap File type: Wireshark/tcpdump/... - libpcap File size: 5740 bytes Data size: 5284 bytes File name: tmp.cap File type: Microsoft NetMon 1.x File size: 5736 bytes Data size: 5284 bytes $
  • 12.
  • 13.