Pages

▼

More info

▼

February 23, 2021

How to Decrypt TLS Traffic in Wireshark Using Session Keys (Chris Greer)

TLS Decryption in Wireshark (Chris Greer)

Chris Greer’s walkthrough on decrypting HTTPS traffic in Wireshark is one of those rare tutorials that makes a pretty intimidating topic feel surprisingly doable. He breaks down how TLS 1.3 session keys work, why you normally can’t peek inside encrypted packets, and how a simple environment variable on Windows lets you capture those keys right from your browser. It’s approachable, but still nerdy enough to scratch that packet‑analysis itch.

The core trick is setting the SSLKEYLOGFILE environment variable so Chrome writes out the session keys as it negotiates TLS. Once you’ve got that log file, Wireshark can use it to decrypt the encrypted streams in real time. Chris walks through the exact steps—Control Panel, Advanced System Settings, Environment Variables—and shows how to plug the keylog into Wireshark’s TLS preferences. If you’ve ever wanted to see what’s actually happening inside HTTPS without guessing, this is the cleanest path in.

February 22, 2021

How to Remotely Stop a Wireshark Capture When Using Tshark or Dumpcap

How to Remotely Stop a Wireshark Capture When Using Tshark or Dumpcap

One of the advantages of installing Wireshark, is working with and learning the various command line utilities that come along with it. Programs like tshark and dumpcap allow you to capture from the command line. This gives the analyst a lot of flexibility in the field.

For example, you might create a shortcut on a client’s desktop so they can capture packets for you. You can also create a batch file so the system starts capturing when it powered on, which is very helpful when I build remote capture devices.

Tshark and dumpcap can capture with specific parameters like ring buffers, filters, etc.

One popular question I get asked is how to stop dumpcap or tshark after you start it. Normally you would press Ctrl+C to stop the capture. I have to admit that the solution I came up with, is not very elegant, but works.

February 18, 2021

Eat That Frog! for Students: A Review (Paul W. Smith)

 

Eat That Frog! for Students: A Review (Paul W. Smith)

I approached this book as a life-long learner, undaunted by the promised focus on students. From this perspective, the lessons apply to both college students and those in a career where progress requires keeping up with the latest knowledge. Eat That Frog! For Students by Brian Tracy is much more than just the time-management book noted on the cover – it outlines a life-sized strategy for success in the context of a detailed plan for dispatching undesirable tasks and dealing with the stress that life inevitably brings, both in and out of school.

February 17, 2021

New Videos Give IT’s Job A Humorous Touch (Keith Bromley)

 Author –


Need a chuckle along with some valuable information that could make your IT jobs easier? Then look no further and check out these two videos:

New Videos Give IT’s Job A Humorous Touch (Keith Bromley)


Both videos illustrate current IT problems. The first problem refers to about complex it has become to test your network. Validation is a critical function as it lets us find out the truth about our network and how well it is, or is not, functioning. The good news is that there are applications available that make this effort much easier now.

February 15, 2021

Norvado Case Study - NetAlly

 

Norvado Case Study - NetAlly

OVERVIEW

Norvado is Northwest Wisconsin's premiere local broadband technology provider. Founded in 1950, Norvado brings cutting-edge technology to Bayfield County, keeping communities connected, vibrant, and competitive with big-city offerings.

February 08, 2021

Measure-Command in PowerShell: The One-Line Script for Real-World Network Performance Testing



 If you want to see a Network person fall under their desk in the fetal position, ask them to write a script. 

A Single Line Powershell Performance Command
Scripts can get complicated since you have to learn a programming language only to find out afterwards that you learned the ‘old not cool anymore’ language. Then you have to document the script using comments and flowcharts, etc…

Ok, let me show you a single Powershell command that you can write to impress your friends, family and maybe your colleagues. The command is Measure-Command {command}. And here is an example from my video Measure-Command {xcopy 113MB h:\*.* /Y}. Its pretty straightforward; Powershell will record how long it takes to complete whatever command you provide. 

In the previous example, it was a xcopy from my local drive to my h: network drive.

February 03, 2021

Top 10 Wireshark Filters (Chris Greer)

 

Top 10 Wireshark Filters (Chris Greer)

The filtering capabilities of Wireshark are very comprehensive. You can filter on just about any field of any protocol, even down to the HEX values in a data stream. Sometimes though, the hardest part about setting a filter in Wireshark is remembering the syntax.

So below are the most common filters that I use in Wireshark. Please comment below and add any common ones that you use as well.

ip.addr == 10.0.0.1
[Sets a filter for any packet with 10.0.0.1, as either the source or dest]

February 01, 2021

Crossing the 10 Million Mark: DDoS Attacks in 2020 ( Richard Hummel, Carol Hildebrandon)

Crossing the 10 Million Mark: DDoS Attacks in 2020 ( Richard Hummel, Carol Hildebrandon)

DDoS Attacks in 2020

Not all world records are cause for celebration—just look at the DDoS attack numbers from 2020. For the first time in history, we observed more than 10 million DDoS attacks in a single year, with NETSCOUT’s ATLAS Security Engineering and Response Team (ASERT) observing 10,089,687 attacks over the course of the year. That’s nearly 1.6 million more attacks than 2019’s count of 8.5 million.