Wireshark Tips for Packet Detective

FTP

Right-click a packet, "Follow TCP Stream"


Telnet

Use the Display Filter for telnet Use the Display Filter for ftp

Right-click a packet, "Follow TCP Stream"


VoIP

From the menu, Telephony, "VoIP Calls". Select a call, click Player.

Check the "Use RTP Timestamps" box and click Decode.

Play the streams. Headphones help.


More Fun with Wireshark

These things are not part of the Packet Detective system, but they're fun to try.

Heartbleed

How to perform a Heartbleed attack

Plaintext Logins at Colleges

Johns Hopkins

Stanford

Ethical Disclosure: I notified these schools in Dec. 2013, as well as dozens of other schools. They just don't care.

HTTP Basic Authentication

Password-protected lecture notes

Hold Security

These are the guys with the "1.2 Billion Stolen Passwords" story. Check out the process of testing your password. The password submission screen has been controversial , and appears to be down now. But even the registration page is fun to sniff, sending your email out in plaintext:

Hold Security has the answer!

SMTP

Use the Display Filter for smtp

Right-click a packet, "Follow TCP Stream"


Last revised: 8-8-14 7:51 am