filmov
tv
Wireshark Packet Editing

Показать описание
Editing a Packet With Wireshark
NOTE : NO LONGER SUPPORTED IN THE CURRENT VERSION OF WIRESHARK
There are many situations where you wish you could share a trace file with a vendor but you can’t because the packets may contain corporate information, IP addresses, passwords, etc.
Wireshark has an experimental feature under Edit Preferences called Enable Packet Editor which does exactly what is says. You can edit anything in the packet at any layer. In this example, I changed a CDP Device ID and CDP’s checksum. I am surprised that Wireshark doesn’t have a more comprehensive packet edit tool, but happy they are making headway.
This technique doesn’t scale well or isn’t practical is you needed to modify 1,000 packet’s, but I still find it helpful and hope the Wireshark development team continues to build on this cool feature.
Please keep in mind that you should only share real corporate packets that you are familiar with and with vendors you trust. I’ve received many trace files that contained more information than the customer was aware of.
NOTE : NO LONGER SUPPORTED IN THE CURRENT VERSION OF WIRESHARK
There are many situations where you wish you could share a trace file with a vendor but you can’t because the packets may contain corporate information, IP addresses, passwords, etc.
Wireshark has an experimental feature under Edit Preferences called Enable Packet Editor which does exactly what is says. You can edit anything in the packet at any layer. In this example, I changed a CDP Device ID and CDP’s checksum. I am surprised that Wireshark doesn’t have a more comprehensive packet edit tool, but happy they are making headway.
This technique doesn’t scale well or isn’t practical is you needed to modify 1,000 packet’s, but I still find it helpful and hope the Wireshark development team continues to build on this cool feature.
Please keep in mind that you should only share real corporate packets that you are familiar with and with vendors you trust. I’ve received many trace files that contained more information than the customer was aware of.