Tuesday, December 2, 2008

Not my usual stuff :-)

My gmail popped up an email with the subject "The case for network traffic filtering". It was from SearchSecurity.com enclosing an article titled "Writing Wireshark network traffic filters".

I had just then been looking at a tcpdump for some arp traffic. Naturally I clicked on the heading. The first paragraph made a reference to an earlier introductory post so like any good engineer I decided to go systematically (sic! ;-) and read that one first.

The introduction is nicely written and very easy to follow. It has several images for illustration but at the same time does not go even near looking like any of the D-rated instruction manuals with screen snapshots :-)

It has the feel of having been written by someone who knows what he's (Mike Chapple) talking about; quoting from the introduction "The best way to become an expert quickly is to get your hands dirty and start capturing network traffic" :-)

I not only emailed the 2 URLs to friends at my former office in Bangalore, I also wrote up this quick post and put it up on my blog... for posterity :-)

The introduction: Wireshark tutorial: How to sniff network traffic

What got me writing this post: Writing Wireshark network traffic filters

And finally here is the Wireshark Manual from the wireshark homepage.

Happy sniffing ;-)

No comments:

Post a Comment