This builds off of Sniffing Networks Part 3- Understanding what you’re seeing. This article introduces another tool to use for network sniffing and compares it to the previously mentioned Wireshark. You’ve already been introduced to Wireshark and learned how to use it. We now consider another tool, Colasoft Capsa Enterprise Edition, which can be used for network sniffing as well. Colasoft Capsa offers many of the same features as Wireshark and introduces new features in analysis. Similar to Wireshark, Colasoft Capsa captures and decodes packets, and supplies a hex view of each packet. Below is a screenshot of the packet view in Colasoft Capsa. Both programs automatically color code protocols. Colasoft Capsa allows you to apply filters to view select types[…]
Category: software
This article builds off of the Sniffing Networks series and introduces Colasoft Capsa Enterprise Edition, which can be used for network sniffing and analysis. To get started capturing packets with Colasoft Capsa, click on the “Start Capture Now” button on the opening screen. Clicking this will open the project settings, which can be customized depending on the project. The project settings can also be modified later by the toolbar at the top of the window. Click OK to get started. This starts the capture which can be stopped at any time by clicking the stop button along the top toolbar. After capturing packets there will be two additional docked windows to the left, and the main window now contains ten[…]
The digital world is moving online and taking our email with it. While most home users have abandoned desktop email clients, most corporate computers are loaded with some desktop email client (almost always Microsoft Outlook), which will keep it alive. Lifehacker posed the question, is Thunderbird and desktop email in general, going extinct? Here are 3 reasons desktop email will continue to live and why corporate administrators won’t pull the plug. Digital Signatures – Online email simply does not handle digital signatures natively. Control – Carting your email out-of-house puts email in the control of another company completely and is a potential security risk. While I think that eventually you’ll begin to see larger and larger companies getting involved in[…]
Mainstream media is beginning to sound the alarms about the Conficker-C worm which is believed to be affecting more than 2 million Windows PCs. Conficker spreads by an RPC-DCOM flaw in Windows, as well as by network shares–logging into machines that use weak passwords–and by removable media. There is a trigger in the code to download new instructions on April 1st, 2009. Much like the Mydoom or the Sobig worms of years past, researchers know a date when an update is expected to occur, but don’t know exactly what will happen. And, much like those years past, it is likely that not much will occur. Microsoft along with other security researchers created the Conficker Cabal which has put a $250,000.00 bounty[…]
This tool for Microsoft Windows gives the user some very important information regarding running processes. It displays a very detailed (and real-time) list of files/directories accessed by a running program. This includes loaded DLLs and file system handles opened or closed during execution. The security benefits of this tool are based around detection and troubleshooting. It is common for malware to inject DLLs into running processes. With this tool, such a compromise could be easy to detect or track down. In addition to individual process information, Process Explorer also reports overall system information– memory usage, processor usage, physical memory activity, etc. In many ways, it is like an improved version of Windows Task Manager. It’s relatively small in size, and[…]
Some may remember a while back NBC (television network) was all primed about showing reruns with the notion “If you haven’t seen it, it’s new to you.” – That’s pretty much what I’m shooting for here. Let’s face it; things in the security industry are always changing. There is always something new to be learning. Software is being updated, new vulnerabilities are being found. Even the cores of what we work with, the operating systems, are changing on a more frequent pace. Over the course of several posts I’m going to be highlighting some of the new features released in the Vista / Server 2008 (and soon to be released Windows 7) upgrades. Again, you might be thinking Vista has[…]