January 25, 2021

A Quick Note About TCP Sequence Numbers

A Quick Note About TCP Sequence Numbers
I’ve received a lot of feedback from my readers expressing their gratitude that my articles/videos are short and to the point. 

To those people who took the time to send their feedback, thank you.

In this video, I briefly discuss TCP sequence numbers and acknowledgements, recognizing that this topic can often be very overwhelming. I keep the explanation quick and simple, focusing on a stream of traffic flowing from a server on port 443 to a client. Make sure you have Wireshark installed and follow along.

January 15, 2021

Our Curious Habits (Paul Smith)

 

Our Curious Habits (Paul Smith)

As an engineer, I’m often accused by my non-engineer brethren of being overly analytical. I confess that I can’t help scrutinizing some things (well...most things) to try and figure out how they work. This can lead to satisfaction and a boost in self-assurance when things work as expected, and a compulsive drive for further analysis when they don’t. I have been blessed (cursed?) with this inclination for as long as I can remember. I have been formally trained for it in school and throughout my career. Reinforced by a lifetime of use, this habit is unlikely to ever change.

January 06, 2021

Wireshark Display Filter Tip: Show Specific Frame Numbers

 

Try this Wireshark display filter
Wireshark’s features can really be a catch 22. In one way, they are very powerful but on another hand, many of them are difficult to find. Every so often I find a gem of a tip or trick which makes packet analysis a lot easier.

In this video I share a different kind of display filter that you may not be familiar with. I’m sure you have used MAC, IP address, TCP, UDP and maybe even some application layer display filters. I find that sometimes I need to display just a few packets that might not have MAC, IP, TCP or UDP port numbers in common.

As you will see in the video, one way to address this challenge is to simply Mark the packets and then apply a display filter for just marked packets. The other way is to use the following display filter syntax frame.number in {frame numbers} this will simply display any frame number you provide in the curly braces.

By focusing on a lesser‑known display filter, I demonstrate how to cut through noisy captures and quickly zero in on the traffic you actually need to inspect.

December 15, 2020

Wireshark Tutorial - Find TCP Delays (Chris Greer)

Wireshark Tutorial - Find TCP Delays (Chris Greer)
Chris Greer’s Wireshark Tutorial: Fixing Slow Applications is a sharp, practical walkthrough that shows you how to pinpoint performance bottlenecks within your  trace files. The video focuses on a clever filtering technique Greer uses to quickly isolate slow connections—an approach that saves time, cuts through noise, and helps you zero in on the real pain points. If you’ve ever stared at a huge capture file wondering where to begin, this tutorial gives you a clear, confident starting point.   

The Science of Pretty Much Anything (Paul W. Smith)

 

The Science of Pretty Much Anything (Paul W. Smith)
In the late sixties, I spent several summers working in a gas station. I learned how to rebuild brakes, mount and balance tires, and perform basic maintenance and repair tasks. I also pumped gas.

For those too young to remember, these were the days when you would pull into a gas station and someone would pump your gas, check your cars fluids, fill up your tires, and wash your windows. I was also taught to look for opportunities to sell tires, batteries, wiper blades and replacement fluids. Although it was essentially a sales job, it gave me an opportunity to learn some basic auto mechanics which probably saved me a lot of money with my own NCPO (non-certified pre-owned) cars.

Popular post in the past 30 days