Jasper

5.6K posts

Jasper banner
Jasper

Jasper

@PacketJay

Head of Incident Response @gdata_adan. Creator of TraceWrangler. Member of the Board of Directors of the #Wireshark Foundation. My thoughts are my own.

Düsseldorf, Germany Присоединился Nisan 2013
1.5K Подписки4.5K Подписчики
Закреплённый твит
Jasper
Jasper@PacketJay·
Starting a series of tips & tricks for #Wireshark in anticipation of #CLUS and #SF19US. So here we go: Wireshark May 2019 Tip #01: you can use the F7/F8 function keys to scroll through the packet list even if the focus is in the decode or packet bytes pane. #wiresharktips #dfir
GIF
English
4
50
132
0
Jasper
Jasper@PacketJay·
@awakecoding Have you considered presenting this kind of talk at Sharkfest? Looks like an interesting topic 😉
English
1
0
0
55
Jasper ретвитнул
Marc-André Moreau
Marc-André Moreau@awakecoding·
If you missed the webinar, here is the video recording for "Decrypting RDP Traffic in Wireshark"! The slides are great, but the one-hour presentation is even better: youtube.com/watch?v=VUHucX…
YouTube video
YouTube
English
1
9
58
4.4K
Jasper ретвитнул
WireSharkFest
WireSharkFest@wiresharkfest·
Check out more agenda highlights from the upcoming #sf24eu #Wireshark Dev & User conference: - Beyond Network Latency: Chasing it up the Stack(Josh Clark) - Kerberos Deep Dive(Eddi Blenkers) - Passive Fingerprinting Methods for #IoT Profiling(Asaf Fried) sharkfest.wireshark.org/sfeu
English
0
4
9
506
Jasper
Jasper@PacketJay·
@danieldibswe @Peter_Paluch some professional FPGA based capture devices allow capturing the FCS in cases where that's needed to troubleshoot physical errors. Standard NICs don't, even though there were COTS PCMCIA cards that could when used with a special driver in Sniffer Pro
English
1
0
2
155
Daniel Dib
Daniel Dib@danieldibswe·
I was researching something and found this old post from Nick Russo. It's actually an interesting discussion whether to count FCS or not.
Daniel Dib tweet media
English
2
4
45
4.4K
Jasper ретвитнул
WireSharkFest
WireSharkFest@wiresharkfest·
Don’t miss your chance to join the industry's best @ SharkFest'24 EUROPE—register to get a spot at the ultimate #Wireshark event. Level up your network analysis skills w/ expert-led sessions & hands-on labs that will transform your approach to networking! sharkfest.wireshark.org/sfeu
WireSharkFest tweet media
English
0
2
2
377
Jasper ретвитнул
WireSharkFest
WireSharkFest@wiresharkfest·
Here are some agenda highlights from the upcoming #sf24eu conference! - Capturing WiFi7 (@ikeriri) - Mastering #Wireshark Filtering (@SYNbit) - IPsec VPN Analysis & troubleshooting (Jean-Paul Archier) Join us in Vienna, Austria this fall! (4-8 Nov): sharkfest.wireshark.org/sfeu
English
0
7
14
1.6K
Jasper ретвитнул
WireSharkFest
WireSharkFest@wiresharkfest·
More agenda highlights from the upcoming #sf24us conference! 
- Advanced #TCP Troubleshooting (@PacketJay) 
- Filters from a novice; Back to the Basics (Kirsten Stoner, Karinne Bessette) 
- Enhancing Wi-Fi Networks with AI (Murat Bilgic)
 Join us: sharkfest.wireshark.org/sfus
English
0
3
8
868
Jasper
Jasper@PacketJay·
@rknall @LauraChappell A few years after writing this blog post I can still say that there's nothing I've seen that is more than a Denial of Service at best (meaning, making Wireshark crash and close) - and I doubt that was really the intention. Just don't run Wireshark as root. Period. 😅
English
0
2
3
164
Roland Knall
Roland Knall@rknall·
@LauraChappell we had a discussion a week ago about this, and I forgot that Jasper already had a blog entry about it. But I think this article will answer a few questions you raised in your comment.
English
1
1
1
232
Jasper ретвитнул
Roland Knall
Roland Knall@rknall·
It pops up now and then: Why should you not run #Wireshark as Administrator/root. There are quite a few reasons for that, but a very good discussion about this topic has been written quite a while ago by @PacketJay and I just wanted to bring it up again: blog.packet-foo.com/2018/09/attack…
English
2
7
19
2.8K
Jasper
Jasper@PacketJay·
@rknall @TracketPacer @SYNbit Tracewrangler removes all sensitive details by default, unless you change settings of the anomymization task. So if you run it on your captures with a default task you should be good 😉
English
0
0
1
39
TracketPacer
TracketPacer@TracketPacer·
i need wireshark footage (essentially just B roll) for videos but i’m struggling to understand what all i need to sanitize besides the obvious: - anything re: my public IP - anything re: my geo location - all the nasty switch licking fetish sites i visit …any tips?
English
76
8
228
38.4K
Jasper ретвитнул
Peter Wu
Peter Wu@Lekensteyn·
Hello #FOSDEM 2024! Hit me up if you want #Wireshark stickers 😁
Peter Wu tweet media
English
0
4
12
1.5K
Jasper
Jasper@PacketJay·
@KarstenIwen Correct. It's just that I have an ongoing IR at hospital right now, and they're really vulnerable due to low IT budgets and keep postponing MFA. Not using MFA is russian roulette by now, for anyone offering remote access, especially when auth'ed against the AD.
English
0
0
3
110
Karsten Iwen
Karsten Iwen@KarstenIwen·
And not only hospitals. This is a must-have for every remote access VPN.
Jasper@PacketJay

To all the IT staff at #hospitals out there: do me (and more than that, yourself) a favor and put mandatory MFA on your VPNs *now*. If you think that's expensive there is something even more expensive in orders of magnitude: #ransomware guys using your VPN to encrypt you. #DFIR

Lübeck, Germany 🇩🇪 English
1
0
2
315