In this video we take a peek at how an ARP Poison attack really works. Instead of just downloading a tool like Ettercap and hitting "Go", we want to know what really happens under the hood. This way we can quickly spot ARP Poison behavior if we are ever the target of a man-in-the-middle.
In a future video, we will look at how to set pre-saved filters in Wireshark to quickly spot this behavior.
One of the common questions I get asked is “What tools do you take on a job?”.
Trying not so sound like an infomercial or typical consultant 😉, I always start with the same response, “depends what you’re doing”.
Troubleshooting, design, installation and training obviously have their differences. Even if I zero in on the most obvious category of troubleshooting, there are still many variables to consider. This is best illustrated with examples.
When troubleshooting performance problems for a client/network that I am familiar with, I usually bring a tap, packet capture tool and my paper notebook. But if I was working on an unfamiliar network, I might want to bring a network discovery tool or software.
This is where my video comes in. Here I recommend to bring the appropriate cables as well as a good old USB flash drive. Since they are inexpensive, I’m in the habit of leaving them in my various tool bags.
The other pro to using the USB drives is that you can use it in Windows, Linux, Apple, Android and other operating systems. I also carry around USB extension cable and microusb/usb adapter in case want to copy data from the USB drive to my phone.
While typing this out, I realized that I missed something; tool bags or cases.
When I use any tool, the first thing is check out the bag or case that it came in since you usually put cables, adapters and other related stuff with the tool.
It drives me crazy when a vendor provides a case that is a real tight fit for its tool that you cant even get the tool back into, let alone space for your cables, adapters or other items you might need for your job. Sometimes I find myself reusing bags from larger tools for smaller tools, or have some larger bags that I keep specific stuff in.
I encourage you to build your own tool bag and let me know what you put in yours.
Some long-time Wireshark users commented that it was a good refresher and they actually learned a thing or two, while others new to Wireshark enjoyed the info and pace.
In this installment of his "2 bits" video series, network trainer and consultant Tony Fortunato tackles a recurring frustration he sees in the field: physically damaged network cables still being used in production. He points to common culprits like broken RJ45 connector tabs, torn or split cable cladding, and the classic move of splicing two cables together and wrapping the joint in electrical tape.
Need to find a debugging program that meets your needs? There are plenty of options out there, so you need to know which one will give you what you're looking for. Wireshark, Firebug and Fiddler are all good options, so let's take a look and see how they compare.