<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8522588641740201139</id><updated>2011-07-28T14:05:10.251-07:00</updated><category term='email worm'/><category term='colasoft'/><category term='large traffic'/><category term='tcpdump'/><category term='protocol'/><category term='Email Privacy'/><category term='MSN'/><category term='Email Monitor'/><category term='security'/><category term='howto'/><category term='InfiniStream'/><category term='Network General'/><category term='network malfunction'/><category term='Packet sniffer news'/><category term='network intrusion'/><category term='nGenius'/><category term='Unipeek'/><category term='http'/><category term='wireshark'/><category term='Kismet'/><category term='NetScount'/><category term='packet sniffer ABC'/><category term='BitTorrent'/><category term='traffic analytics'/><category term='colasoft capsa'/><category term='Public Key Encryption'/><category term='Colasoft MAC Scanner'/><category term='bandwidth'/><category term='packet sniffer howto'/><category term='etherdetect'/><category term='wireless'/><category term='monitor'/><category term='network security'/><category term='internet'/><category term='chat'/><category term='MAC address'/><category term='packet sniffer article'/><category term='performance'/><category term='end point'/><category term='network'/><category term='packet sniffer'/><category term='monitor traffic'/><category term='IT Management'/><category term='network analyzer'/><category term='ettercap'/><category term='traffic'/><title type='text'>SnifferClub - Free Packet Sniffer Software Download, Review, Howto's and Articles</title><subtitle type='html'>SnifferClub is a place we can download and discuss, free, hot, new, best packet sniffer software on the planet. Share packet sniffer knowledge, packet sniffer software reviews, packet sniffer software news.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>33</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-2562409956978231040</id><published>2009-06-24T02:59:00.000-07:00</published><updated>2009-06-24T03:07:18.273-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='howto'/><category scheme='http://www.blogger.com/atom/ns#' term='email worm'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>How to Detect Email Worm with Colasoft Packet Sniffer</title><content type='html'>&lt;strong&gt;What Is an Email Worm&lt;/strong&gt;&lt;br /&gt;In networking, an email worm is a computer worm which can copy itself to the shared folder in system. And it will keep sending infected emails to stochastic email addresses. In this way, it spreads fast via SMTP mail servers.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;What Is the Harm of Email Worm&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;An email worm can send lots of infected emails in a very short time and it will never stop unless it’s removed. It will cause a large traffic and make the system go slowly. Sometimes it even makes the mail server crash.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;How to Detect Email Worm&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;If you are suspicious some host in your network is infected with an email worm, here is a process how we can &lt;strong&gt;&lt;a href="http://blog.colasoft.com/how-to-detect-email-worm-with-colasoft-packet-sniffer/" title="how to detect email worm"&gt;detect email worm"&lt;/a&gt;&lt;/strong&gt; in network with Colasoft &lt;a title="Colasoft Packet Sniffer" href="http://www.colasoft.com/capsa/?prid=csblog" target="_blank"&gt;Packet Sniffer&lt;/a&gt;, step by step.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&amp;gt;&lt;em&gt;Step1. &lt;a title="Download Colasoft Packet Sniffer" href="http://www.colasoft.com/download/products/capsa.php?prid=csblog" target="_blank"&gt;Download a free trial&lt;/a&gt; and &lt;a title="deploy colasoft packet sniffer correct" href="http://www.colasoft.com/support/installation.php?prid=csblog" target="_blank"&gt;deploy it properly&lt;/a&gt;.&lt;/em&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&amp;gt;&lt;em&gt;Step2. Launch a Project and Start Capturing Some Traffic.&lt;/em&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&amp;gt;&lt;em&gt;Step3. Switch to “Diagnosis” Tab&lt;/em&gt;&lt;br /&gt;&lt;br&gt;Diagnosis tab is a view we can see all the network issues automatically detected by Colasoft Packet Sniffer, also some causes and solutions are suggested.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/detect-email-worm-ss1.gif"&gt;&lt;img class="size-full wp-image-289" title="Click to View Large" src="http://blog.colasoft.com/wp-content/uploads/2009/06/detect-email-worm-ss1.gif" alt="Diagnosis Tab Screenshot" width="480" height="360" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;If there is a host infected with an email worm, we should be able to see SMTP events in the application layer like this:&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/detect-email-worm-ss2.jpg"&gt;&lt;img class="size-full wp-image-291" title="SMTP Events in Application Layer" src="http://blog.colasoft.com/wp-content/uploads/2009/06/detect-email-worm-ss2.jpg" alt="SMTP Events in Application Layer" width="401" height="138" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&amp;gt;&lt;em&gt;Step4. Locate the Source IP&lt;/em&gt;&lt;br /&gt;&lt;br&gt;Possibly the source IP is the host infected with an email worm as it is sending too many emails in a short period of time with SMTP. So let’s locate the source IP in the “Explorer” with the “Locate” shortcut in the right-click menu.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/detect-email-worm-ss3.gif"&gt;&lt;img class="size-full wp-image-293" title="Click to view large" src="http://blog.colasoft.com/wp-content/uploads/2009/06/detect-email-worm-ss3.gif" alt="Locate Source IP" width="480" height="360" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&amp;gt;&lt;em&gt;Step5. Switch to “Logs” Tab&lt;/em&gt;&lt;br /&gt;&lt;br&gt;Check if the host is sending emails to a large number of recipients in a very short period of time. If so, we can determine the host is infected with an email worm and should be handled immediately. We should be able to see logs in the Tab like this:&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/detect-email-worm-ss4.jpg"&gt;&lt;img class="size-full wp-image-294" title="View Email Logs in &amp;quot;Logs&amp;quot; Tab" src="http://blog.colasoft.com/wp-content/uploads/2009/06/detect-email-worm-ss4.jpg" alt="View Email Logs in &amp;quot;Logs&amp;quot; Tab" width="433" height="117" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;No doubt the final step is to isolate the host and kill the email worm with some AV software&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Also there will be some other process to detect email worm with Colasoft Packet Sniffer, this is the shortest one.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-2562409956978231040?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/2562409956978231040/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-detect-email-worm-with-colasoft.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/2562409956978231040'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/2562409956978231040'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-detect-email-worm-with-colasoft.html' title='How to Detect Email Worm with Colasoft Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-7695890469757915839</id><published>2009-06-17T03:23:00.000-07:00</published><updated>2009-06-17T03:28:49.605-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network analyzer'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft capsa'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>14 Tips to Protect Your Organization's Network</title><content type='html'>&lt;a href="http://www.colasoft.com/?prid=00060003"&gt;&lt;img id="Colasoft Network Analyzer" style="FLOAT: right; MARGIN: 0px 0px 10px 10px; WIDTH: 125px; CURSOR: hand; HEIGHT: 125px" alt="Colasoft Network Analyzer" src="http://3.bp.blogspot.com/_LCrZaQE-Vo8/SjdshqFnnLI/AAAAAAAAFEg/WgJ38NcmnmM/s400/125_125_2.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;Network security is an infinitely complex and dynamic subject, implementing these &lt;a href="http://topnetworksniffers.blogspot.com/2009/06/14-tips-to-protect-your-organizations.html"&gt;simple measures &lt;/a&gt;will go a long way to protecting your Organization's LAN.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;1,&lt;strong&gt; Run &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;Network Analyzer&lt;/a&gt; Frequently.&lt;/strong&gt;Recommend an easy-to-use network analyzer, &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;Colasoft Capsa&lt;/a&gt;. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;2, &lt;strong&gt;Disable drives&lt;/strong&gt;:Disable floppy drive access, USB ports and serial ports on networked computers.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;3,&lt;strong&gt; Restrict Permissions&lt;/strong&gt;: Windows 2000 and 2003 server allow you to set permissions so that users can't run downloaded 'exe' or other executable files. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;4,&lt;strong&gt; Block Instant Messenger&lt;/strong&gt;:IM and its cousins, ICQ and Yahoo Messenger, sends messages and attachments out to a server and then back to its clients. You lose control when this happens.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;5,&lt;strong&gt; Password Protect Your BIOS&lt;/strong&gt;:A BIOS without an administrator password is an invitation to mischief. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;6,&lt;strong&gt; Run AV Software&lt;/strong&gt;: Run anti-virus software on all your computers.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;7,&lt;strong&gt; Build Your Defenses&lt;/strong&gt;: Install a firewall or a proxy server.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;8,&lt;strong&gt; Beware Of Attachments From Unknown, Untrusted Sources&lt;/strong&gt;:Do not open attachments to email unless you trust the sender.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;9,&lt;strong&gt; Monitor Your Ports&lt;/strong&gt;:Install a port monitor to prevent your ports from being scanned.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;10,&lt;strong&gt; Encrypt Wireless Access&lt;/strong&gt;.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;11,&lt;strong&gt; Keep Back Office Systems Off The Organization Network&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;12,&lt;strong&gt; Require passwords to be changed frequently&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;13,&lt;strong&gt; Use CTRL+ALT+DEL to logon&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;14,&lt;strong&gt; Keep your networking skills up to date.&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-7695890469757915839?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/7695890469757915839/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/06/14-tips-to-protect-your-organizations.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/7695890469757915839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/7695890469757915839'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/06/14-tips-to-protect-your-organizations.html' title='14 Tips to Protect Your Organization&apos;s Network'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LCrZaQE-Vo8/SjdshqFnnLI/AAAAAAAAFEg/WgJ38NcmnmM/s72-c/125_125_2.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-8329906065223213263</id><published>2009-06-11T00:26:00.000-07:00</published><updated>2009-06-11T00:34:54.345-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='traffic analytics'/><category scheme='http://www.blogger.com/atom/ns#' term='end point'/><category scheme='http://www.blogger.com/atom/ns#' term='large traffic'/><category scheme='http://www.blogger.com/atom/ns#' term='network malfunction'/><title type='text'>How to detect the network malfunction via the end-point view with Colasoft Packet Sniffer</title><content type='html'>&lt;P style="TEXT-ALIGN: left"&gt;&lt;STRONG&gt;Brief introduction about the Endpoint view in &lt;A title="Colasoft Packet Sniffer 6.9" href="http://www.colasoft.com/capsa/?prid=00060001"&gt;Colasoft Packet Sniffer&lt;/A&gt;&lt;/STRONG&gt; &lt;/P&gt;&lt;br /&gt;&lt;P style="TEXT-ALIGN: left"&gt;It is divided into Mac endpoint and IP endpoint in Colasoft 6.9. Users can detect the IP/Mac endpoint in the largest traffic in a short time by the endpoint analytics. And also, The system supply clear statistics of traffic ranking(Top 5 IP endpoint under HTTP protocol). &lt;BR&gt;&lt;BR&gt;In the Endpoint view, we can see the specific traffic situation clearly of all the hosts(Including a network segment, a Mac address, and a IP address) in the currently network. Like the hosts with the largest total traffic, hosts that send/receive the largest traffic, hosts that send/receive the most packets, etc. &lt;BR&gt;&lt;BR&gt;According to this information, we can confirm that if there are Broadcast / multicast storm, and help users detecting the network malfunctions about network slow, network disconnect, worm attack, DOS attack, and all the malfunctions besides. &lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Application case study&lt;/STRONG&gt; Once we meet the network malfunction or attack, what the most important thing we should pay attention to, is the currently total network traffic, sent/received traffic, network connection etc, to get a clear direction to find the problem. And, all of this information are included in the endpoint view in Colasoft Packet Sniffer 6.9(figure 1): &lt;BR&gt;&lt;BR&gt;&lt;A href="https://egqdxw.blu.livefilestore.com/y1mNWiZV65j2wZEQwshKI76yZSBj2zrlVpkqHHps5IEA6OPZlF3sCuF7WCP5qDtG8fOayUYtomMRpXHXwRTrZFqHg1OafNbLX8pSfQFSHUuNjrjRH57z7sGk5QiX0psTRzbet-3jQ25BXC4g-6oMg1F4Q/Untitled-1.jpg" rel=WLPP;url=https://egqdxw.blu.livefilestore.com/y1mNWiZV65j2wZEQwshKI76yZSBj2zrlVpkqHHps5IEA6OPZlF3sCuF7WCP5qDtG8fOayUYtomMRpXHXwRTrZFqHg1OafNbLX8pSfQFSHUuNjrjRH57z7sGk5QiX0psTRzbet-3jQ25BXC4g-6oMg1F4Q/Untitled-1.jpg target=_blank&gt;&lt;IMG alt="" src="https://egqdxw.blu.livefilestore.com/y1mNWiZV65j2wZEQwshKI76yZSBj2zrlVpkqHHps5IEA6OPZlF3sCuF7WCP5qDtG8fOayUYtomMRpXHXwRTrZFqHg1OafNbLX8pSfQFSHUuNjrjRH57z7sGk5QiX0psTRzbet-3jQ25BXC4g-6oMg1F4Q/Untitled-1.jpg"&gt;&lt;/A&gt;&lt;A href="https://egqdxw.blu.livefilestore.com/y1m_gaHEK9AqAsYdu-TnZmVKAHAnfHI1kIFOJvnDGKv_1xsqzgjfK61XqXTUqUNXui_naoqaepPmu8Y2-4vpz1kI-h0yaMecM4bmtP1b747a7eFulZivGU82YGaNlOqxk64GFAFf0csZmHiWy-UEfBzgg/Untitled-2.jpg" rel=WLPP;url=https://egqdxw.blu.livefilestore.com/y1m_gaHEK9AqAsYdu-TnZmVKAHAnfHI1kIFOJvnDGKv_1xsqzgjfK61XqXTUqUNXui_naoqaepPmu8Y2-4vpz1kI-h0yaMecM4bmtP1b747a7eFulZivGU82YGaNlOqxk64GFAFf0csZmHiWy-UEfBzgg/Untitled-2.jpg target=_blank&gt;&lt;/A&gt;&lt;A href="https://egqdxw.blu.livefilestore.com/y1mQrVNfc5QOFsJwyKaaaCsviEb9UPP0foMT3kScJ0TXuPVprNzBE9arAct3pk3YAcNAN3vWbazdU-WfQhEqdcITx6OlIliI9uoA6ZLaIe_wPNsSnD-8TNS_CuzFWhlNsP7oYwoxg5mrvGaKEac-QDC9A/Untitled-3.jpg" rel=WLPP;url=https://egqdxw.blu.livefilestore.com/y1mQrVNfc5QOFsJwyKaaaCsviEb9UPP0foMT3kScJ0TXuPVprNzBE9arAct3pk3YAcNAN3vWbazdU-WfQhEqdcITx6OlIliI9uoA6ZLaIe_wPNsSnD-8TNS_CuzFWhlNsP7oYwoxg5mrvGaKEac-QDC9A/Untitled-3.jpg target=_blank&gt;&lt;/A&gt;&lt;A href="https://egqdxw.blu.livefilestore.com/y1miEiNMOyeedGUHC8L7rw0tzK3QTK4OsW4B0VL5620i7ZiU0xWIuonh0Uyd2DzA6fVaHWUmI5Ovh7BFlN6TFCsDHOBRX_fbHX116iCvsVKZb2ANtTifjtRyt2YdB9uWx2Kfw4-tjxgJMHx1tbUbCfQ-g/Untitled-4.jpg" rel=WLPP;url=https://egqdxw.blu.livefilestore.com/y1miEiNMOyeedGUHC8L7rw0tzK3QTK4OsW4B0VL5620i7ZiU0xWIuonh0Uyd2DzA6fVaHWUmI5Ovh7BFlN6TFCsDHOBRX_fbHX116iCvsVKZb2ANtTifjtRyt2YdB9uWx2Kfw4-tjxgJMHx1tbUbCfQ-g/Untitled-4.jpg target=_blank&gt;&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;In figure 1 we can make a compositor on the total traffic, network connection and other related information, to find and locate the host with largest traffic or most connections in the network. For example, at present, the host with the largest network connection is , we can locate the host, then check the related connection information(figure 2): &lt;BR&gt;&lt;BR&gt;The connection information shown as the figure 2, we can know that has set up a large amount of TCP connection with other hosts, and the destination address and destination endpoint are indefinite, and Many of the state is to connect client requests synchronization.&amp;nbsp;&lt;BR&gt;&lt;A href="https://egqdxw.blu.livefilestore.com/y1m_gaHEK9AqAsYdu-TnZmVKAHAnfHI1kIFOJvnDGKv_1xsqzgjfK61XqXTUqUNXui_naoqaepPmu8Y2-4vpz1kI-h0yaMecM4bmtP1b747a7eFulZivGU82YGaNlOqxk64GFAFf0csZmHiWy-UEfBzgg/Untitled-2.jpg" rel=WLPP;url=https://egqdxw.blu.livefilestore.com/y1m_gaHEK9AqAsYdu-TnZmVKAHAnfHI1kIFOJvnDGKv_1xsqzgjfK61XqXTUqUNXui_naoqaepPmu8Y2-4vpz1kI-h0yaMecM4bmtP1b747a7eFulZivGU82YGaNlOqxk64GFAFf0csZmHiWy-UEfBzgg/Untitled-2.jpg target=_blank&gt;&lt;IMG alt="" src="https://egqdxw.blu.livefilestore.com/y1m_gaHEK9AqAsYdu-TnZmVKAHAnfHI1kIFOJvnDGKv_1xsqzgjfK61XqXTUqUNXui_naoqaepPmu8Y2-4vpz1kI-h0yaMecM4bmtP1b747a7eFulZivGU82YGaNlOqxk64GFAFf0csZmHiWy-UEfBzgg/Untitled-2.jpg"&gt;&lt;/A&gt;&lt;BR&gt;&amp;nbsp;&lt;/P&gt;&lt;br /&gt;&lt;P style="TEXT-ALIGN: left"&gt;Next, check the TCP packets, we can check them out in Summary and Graphic as follows:&lt;A href="https://egqdxw.blu.livefilestore.com/y1mQrVNfc5QOFsJwyKaaaCsviEb9UPP0foMT3kScJ0TXuPVprNzBE9arAct3pk3YAcNAN3vWbazdU-WfQhEqdcITx6OlIliI9uoA6ZLaIe_wPNsSnD-8TNS_CuzFWhlNsP7oYwoxg5mrvGaKEac-QDC9A/Untitled-3.jpg" rel=WLPP;url=https://egqdxw.blu.livefilestore.com/y1mQrVNfc5QOFsJwyKaaaCsviEb9UPP0foMT3kScJ0TXuPVprNzBE9arAct3pk3YAcNAN3vWbazdU-WfQhEqdcITx6OlIliI9uoA6ZLaIe_wPNsSnD-8TNS_CuzFWhlNsP7oYwoxg5mrvGaKEac-QDC9A/Untitled-3.jpg target=_blank&gt;&lt;IMG alt="" src="https://egqdxw.blu.livefilestore.com/y1mQrVNfc5QOFsJwyKaaaCsviEb9UPP0foMT3kScJ0TXuPVprNzBE9arAct3pk3YAcNAN3vWbazdU-WfQhEqdcITx6OlIliI9uoA6ZLaIe_wPNsSnD-8TNS_CuzFWhlNsP7oYwoxg5mrvGaKEac-QDC9A/Untitled-3.jpg"&gt;&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;&lt;A href="https://egqdxw.blu.livefilestore.com/y1miEiNMOyeedGUHC8L7rw0tzK3QTK4OsW4B0VL5620i7ZiU0xWIuonh0Uyd2DzA6fVaHWUmI5Ovh7BFlN6TFCsDHOBRX_fbHX116iCvsVKZb2ANtTifjtRyt2YdB9uWx2Kfw4-tjxgJMHx1tbUbCfQ-g/Untitled-4.jpg" rel=WLPP;url=https://egqdxw.blu.livefilestore.com/y1miEiNMOyeedGUHC8L7rw0tzK3QTK4OsW4B0VL5620i7ZiU0xWIuonh0Uyd2DzA6fVaHWUmI5Ovh7BFlN6TFCsDHOBRX_fbHX116iCvsVKZb2ANtTifjtRyt2YdB9uWx2Kfw4-tjxgJMHx1tbUbCfQ-g/Untitled-4.jpg target=_blank&gt;&lt;IMG alt="" src="https://egqdxw.blu.livefilestore.com/y1miEiNMOyeedGUHC8L7rw0tzK3QTK4OsW4B0VL5620i7ZiU0xWIuonh0Uyd2DzA6fVaHWUmI5Ovh7BFlN6TFCsDHOBRX_fbHX116iCvsVKZb2ANtTifjtRyt2YdB9uWx2Kfw4-tjxgJMHx1tbUbCfQ-g/Untitled-4.jpg"&gt;&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;In the TCP packets information, we found has sent TCP synchronization packet, and the TCP FIN packets and TCP Reset packets are, this is deviant in the network. &lt;/P&gt;&lt;br /&gt;&lt;P style="TEXT-ALIGN: left"&gt;Please go to the &lt;A title="Capsa FAQ" href="http://www.colasoft.com/capsa/network_solution.php?prid=00060001" target=_blank&gt;Colasoft Official FAQ page&lt;/A&gt; for more "How-tos"&lt;/P&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-8329906065223213263?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/8329906065223213263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-detect-network-malfunction-via.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8329906065223213263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8329906065223213263'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-detect-network-malfunction-via.html' title='How to detect the network malfunction via the end-point view with Colasoft Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-8690452718227673140</id><published>2009-06-10T02:54:00.000-07:00</published><updated>2009-06-10T03:02:22.441-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='traffic'/><category scheme='http://www.blogger.com/atom/ns#' term='howto'/><category scheme='http://www.blogger.com/atom/ns#' term='BitTorrent'/><category scheme='http://www.blogger.com/atom/ns#' term='bandwidth'/><title type='text'>How to Track BitTorrent User in Network with Colasoft Packet Sniffer</title><content type='html'>&lt;strong&gt;BitTorrent Consumes Big Bandwidth&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;Based on the working principle of BitTorrent protocol, if somebody is downloading big files with BitTorrent software, it will be a disaster for other users who need bandwidth for business operations as the user will consume large amount of bandwidth, thus causing long time network slowness, intermittence, even disconnections; because meantime the user downloading files from others, others are downloading files from him.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;So it is necessary for IT administrators to track BitTorrent user at first place to regain network bandwidth for business operations. Blocking BitTorrent protocol can be one way; this article is to discuss how to &lt;a href="http://blog.colasoft.com/how-to-track-bittorrent-user-in-network-with-colasoft-packet-sniffer/" title="how to track BitTorrent user"&gt;track BitTorrent user&lt;/a&gt; with &lt;a title="colasoft packet sniffer" href="http://www.colasoft.com/capsa/?prid=00060003" target="_blank"&gt;Colasoft Packet Sniffer&lt;/a&gt;.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;How to Track BitTorrent User?&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;em&gt;&amp;gt;Step1. &lt;a title="Download Colasoft Packet Sniffer Free Trial" href="http://www.colasoft.com/download/products/capsa.php?prid=00060003" target="_blank"&gt;Download a free trial&lt;/a&gt; and &lt;a title="implement packet sniffer correct" href="http://www.colasoft.com/support/installation.php?prid=00060003" target="_blank"&gt;implement it correctly&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;em&gt;&amp;gt;Step2. Launch a project and start capturing data&lt;/em&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;em&gt;&amp;gt;Step3. Find BitTorrent Protocol in the "Protocols" Tab&lt;/em&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/track-bittorrent-user-ss1.jpg"&gt;&lt;img class="size-full wp-image-190" title="Track BitTorrent User Screenshot 1" src="http://blog.colasoft.com/wp-content/uploads/2009/06/track-bittorrent-user-ss1.jpg" alt="Track BitTorrent User Screenshot 1" width="480" height="359" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;em&gt;&amp;gt;Setp4. Locate BitTorrent Protocol in the "Explorer"&lt;/em&gt;&lt;br /&gt;&lt;br&gt;Use the "Locate" function to locate BitTorrent protocol in the "Explorer" to analyze dedicated data.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/track-bittorrent-user-ss2.jpg"&gt;&lt;img class="size-full wp-image-191" title="Track BitTorrent User Screenshot 2" src="http://blog.colasoft.com/wp-content/uploads/2009/06/track-bittorrent-user-ss2.jpg" alt="Track BitTorrent User Screenshot 2" width="480" height="359" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;em&gt;&amp;gt;Step5. Track BitTorrent User in LAN in the "Endpoint" Tab&lt;/em&gt;&lt;br /&gt;&lt;br&gt;This is the way how to track the BitTorrent user in our network and who are connected with him. There is a lot more we can see from this tab, such as how much data has been downloaded and uploaded via BitTorrent protocol.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/track-bittorrent-user-ss3.jpg"&gt;&lt;img class="size-full wp-image-192" title="Track BitTorrent User Screenshot 3" src="http://blog.colasoft.com/wp-content/uploads/2009/06/track-bittorrent-user-ss3.jpg" alt="Track BitTorrent User Screenshot 3" width="480" height="359" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;View how many connections have been built in "Matrix"&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;You’ll be shocked to see how many connections have been built in the "Matrix" Tab. In this case, we can see this user has built more than 1000 connections with other hosts.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/track-bittorrent-user-ss4.jpg"&gt;&lt;img class="size-full wp-image-193" title="Track BitTorrent User Screenshot 4" src="http://blog.colasoft.com/wp-content/uploads/2009/06/track-bittorrent-user-ss4.jpg" alt="Track BitTorrent User Screenshot 4" width="480" height="359" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;About BitTorrent&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;BitTorrent is a peer-to-peer file sharing protocol used for distributing large amounts of data. BitTorrent is one of the most common protocols for transferring large files.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;The protocol works when a file provider initially makes his/her file (or group of files) available to the network. This is called a seed and allows others, named peers, to connect and download the file. Each peer that downloads a part of the data makes it available to other peers to download. After the file is successfully downloaded by a peer, many continue to make the data available, becoming additional seeds. This distributed nature of BitTorrent leads to a viral spreading of a file throughout peers. As more peers join the swarm, the likelihood of a successful download increases. Relative to standard Internet hosting, this provides a significant reduction in the original distributor's hardware and bandwidth resource costs. It also provides redundancy against system problems and reduces dependence on the original distributor.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Next Step&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;&lt;a title="Download Colasoft Packet Sniffer Free Trial" href="http://www.colasoft.com/download/products/capsa.php?prid=00060003" target="_blank"&gt;&amp;gt;&amp;gt;Download a Free Trial&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-8690452718227673140?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/8690452718227673140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-track-bittorrent-user-in-network.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8690452718227673140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8690452718227673140'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-track-bittorrent-user-in-network.html' title='How to Track BitTorrent User in Network with Colasoft Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-3416054445955477064</id><published>2009-06-08T22:26:00.001-07:00</published><updated>2009-06-08T22:26:55.174-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='howto'/><category scheme='http://www.blogger.com/atom/ns#' term='MSN'/><category scheme='http://www.blogger.com/atom/ns#' term='Unipeek'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='chat'/><title type='text'>How to Monitor MSN Chat with Free Unipeek MSN Monitor</title><content type='html'>For some purposes we want to monitor MSN chat around the network, for example, parents want to monitor MSN chat of their kids to ensure their safety; bosses want to monitor MSN chat of employees for company assets security and to improve work efficiency by minimizing none-business chat during working hours. You may still remember Colasoft MSN Monitor, now it is called &lt;a title="Unipeek MSN Monitor" href="http://www.msn-monitor.com/index.php" target="_blank"&gt;Unipeek MSN Monitor&lt;/a&gt; and it is distributed &lt;strong&gt;completely Free&lt;/strong&gt; for none commercial users.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Now let’s see how we can &lt;a title="How to Monitor MSN Chat" href="http://blog.colasoft.com/how-to-monitor-msn-chat-with-free-unipeek-msn-monitor/" target="_blank"&gt;monitor MSN chat&lt;/a&gt; with Unipeek MSN Monitor, the free tool.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Step1. Download Unipeek MSN Monitor&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a title="Download Unipeek MSN Monitor" href="http://www.msn-monitor.com/download_msn_monitor.php" target="_blank"&gt;Download Unipeek MSN Monitor&lt;/a&gt;, the free edition; from the website. As a matter of fact there is no function difference between Unipeek MSN Monitor the free edition and the commercial edition. The only difference is Unipeek MSN Monitor Free Edition only supports 10 MSN accounts maximum, but quite enough for family users.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Step2. Install and Deploy Unipeek MSN Monitor&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;The installation is quick and simple, just click “next” all the way to complete the installation. But the deployment is somewhat different. As Unipeek MSN Monitor is designed based on &lt;a title="Colasoft Network Analyzer Software for Windows" href="http://www.colasoft.com/prid=00060003" target="_blank"&gt;Colasoft&lt;/a&gt;’s packet capturing technology, so it has to be &lt;a title="how to deploy packet sniffer" href="http://www.colasoft.com/support/installation.php?prid=00060003" target="_blank"&gt;deployed properly&lt;/a&gt; like a packet sniffer if you want to monitor all MSN chat around the network. Of course, you don’t have to do it if you only want to monitor MSN chat of a single computer. To monitor multiple computers, you can install multiple copies.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/monitor-msn-chat-ss1.jpg"&gt;&lt;img class="size-full wp-image-179" title="How to Monitor MSN Chat Screenshot 1" src="http://blog.colasoft.com/wp-content/uploads/2009/06/monitor-msn-chat-ss1.jpg" alt="How to Monitor MSN Chat Screenshot 1" width="526" height="376" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Setp3. Run it and Start Monitor MSN Chat&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;After proper installation and deployment, we can start monitoring MSN chat right away.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/06/monitor-msn-chat-ss2.jpg"&gt;&lt;img class="size-full wp-image-180" title="How to Monitor MSN Chat Screenshot 2" src="http://blog.colasoft.com/wp-content/uploads/2009/06/monitor-msn-chat-ss2.jpg" alt="How to Monitor MSN Chat Screenshot 2" width="544" height="408" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;About Unipeek MSN Monitor&lt;/strong&gt;&lt;br /&gt;Unipeek MSN Monitor (MSN sniffer) is Free MSN monitoring software for MSN chat monitoring and MSN message archiving. Based on Colasoft's packet analysis technology, Unipeek MSN Monitor is able to deliver the most accurate MSN monitoring statistics, and automatically record data for future reference. You need only install Unipeek MSN Monitor once to monitor all MSN chats over the local network.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Key Features include:&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;• Real-time and 24/7 MSN chat monitoring&lt;br /&gt;&lt;br&gt;• Automatically archive MSN messages for future reference&lt;br /&gt;&lt;br&gt;• Export messages of a custom time range&lt;br /&gt;&lt;br&gt;• Customize MSN account list to be monitored&lt;br /&gt;&lt;br&gt;• Unique Conversation Matrix showing account relations&lt;br /&gt;&lt;br&gt;• Support emotion icons, message font size and color.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Download Now&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;&lt;a title="Download Unipeek MSN Monitor" href="http://www.msn-monitor.com/download_msn_monitor.php" target="_blank"&gt;Download Unipeek MSN Monitor&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-3416054445955477064?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/3416054445955477064/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-monitor-msn-chat-with-free.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3416054445955477064'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3416054445955477064'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-monitor-msn-chat-with-free.html' title='How to Monitor MSN Chat with Free Unipeek MSN Monitor'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-134399853888057964</id><published>2009-06-08T22:24:00.000-07:00</published><updated>2009-06-08T22:25:59.599-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer'/><category scheme='http://www.blogger.com/atom/ns#' term='Email Monitor'/><category scheme='http://www.blogger.com/atom/ns#' term='howto'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>How to Monitor Emails with Colasoft Packet Sniffer</title><content type='html'>&lt;p&gt;Some people may doubt if it is legal to &lt;a href="http://blog.colasoft.com/how-to-monitor-emails-with-colasoft-packet-sniffer/"&gt;monitor emails&lt;/a&gt; of employees with an email monitor software (aka. email spy or email checker), but this is not the topic of this article. We are going to discuss how we can monitor emails with some technical methods, especially how we can monitor emails with this packet sniffer – Colasoft Capsa.&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Step 1. Still we need to &lt;a title="download colasoft pakcet sniffer free trial" href="http://www.colasoft.com/download/products/capsa.php?prid=00060001" target="_blank"&gt;download a free trial&lt;/a&gt; and &lt;a title="how to deploy packet sniffer" href="http://www.colasoft.com/support/installation.php?prid=00060001" target="_blank"&gt;deploy it correctly&lt;/a&gt;.&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Step 2. Launch a project&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;If we have not set Capsa to save email logs to a local disk, we’ll not be able to monitor email contents but we can monitor all email logs. So we must set the log settings to save email logs to a local path in order to monitor email contents. Also there will be a notice when start a new project.&lt;br /&gt;&lt;p&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss1.jpg"&gt;&lt;img class="size-full wp-image-161" title="Monitor Email Screeshot1 " src="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss1.jpg" alt="Monitor Email Screeshot1 " width="326" height="263" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Setp3. Set Email Logs Settings&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;View full image to set the email logs setting correctly.&lt;br /&gt;&lt;p&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss2.jpg"&gt;&lt;img class="size-full wp-image-163" title="Monitor Email Screenshot2 - Click to view Large" src="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss2.jpg" alt="Monitor Email Screenshot2 - Click to view Large" width="376" height="304" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;Advanced Email logs settings to split email logs and keep the most recent email logs to save disk space.&lt;br /&gt;&lt;p&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss3.jpg"&gt;&lt;img class="size-full wp-image-166" title="Monitor Email Screeshot3" src="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss3.jpg" alt="Monitor Email Screeshot3" width="412" height="358" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Step 4. Start Capturing and Monitoring Emails in “Logs” Tab&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;After email log settings is finished, we can do a test to see if we can get some email monitoring logs. Let’s launch Outlook and start sending and receiving emails. We can see that we’ve received many spam email in my email box. We can see a lot of information in the logs Tab, such as date and time, client name, email subject, sender and receiver name, size, and more.&lt;br /&gt;&lt;p&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss4.jpg"&gt;&lt;img class="size-full wp-image-158" title="Monitor Emails Screeshot - Click to View Large" src="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss4.jpg" alt="Monitor Emails Screeshot - Click to View Large" width="480" height="360" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Step 5. Monitor Email Contents&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;In order to view the original content of an email, the process is quite simple, just double-click on the logs, then Capsa will call an email software to display the email content, basically Outlook.&lt;br /&gt;&lt;p&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss5.jpg"&gt;&lt;img class="size-full wp-image-169" title="Monitor Email Screeshot5 - Click to View Large" src="http://blog.colasoft.com/wp-content/uploads/2009/05/monitor-email-ss5.jpg" alt="Monitor Email Screeshot5 - Click to View Large" width="500" height="367" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;Now this is the entire process how we can monitor emails with Colasoft Capsa, we hope you enjoy this article.&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Next Step&lt;/strong&gt;&lt;br /&gt;&lt;br&gt;&amp;gt;&amp;gt;&lt;a title="download colasoft packet sniffer free trial" href="http://www.colasoft.com/download/products/capsa.php?prid=00060001" target="_blank"&gt;Download a Free Trial&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-134399853888057964?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/134399853888057964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-monitor-emails-with-colasoft.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/134399853888057964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/134399853888057964'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/06/how-to-monitor-emails-with-colasoft.html' title='How to Monitor Emails with Colasoft Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-9216063719614277952</id><published>2009-05-14T02:54:00.000-07:00</published><updated>2009-05-14T03:04:43.135-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer'/><category scheme='http://www.blogger.com/atom/ns#' term='protocol'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><category scheme='http://www.blogger.com/atom/ns#' term='network intrusion'/><title type='text'>Ten Reasons Make Packet Sniffers an Essential Network Tool</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/?prid=03060003"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 231px;" src="http://1.bp.blogspot.com/_LCrZaQE-Vo8/SgvWOTAmB7I/AAAAAAAAFDc/eVCt2TNJuZ4/s320/Colasoft_Capsa___Expert_Packet_Sniffer_14559.gif" alt="colasoft packet sniffer" id="colasoft packet sniffer" border="0" /&gt;&lt;/a&gt;No matter  whether you are network administrators or IT managers, you should not be  unfamiliar to the network analysis tool - &lt;a href="http://www.colasoft.com/capsa/?prid=03060003"&gt;packet sniffer&lt;/a&gt;, also known as a  &lt;strong&gt;network analyzer, protocol analyzer or sniffer&lt;/strong&gt;) which has been widely used by  kinds of organizations, schools, enterprises, government institutions etc.&lt;br /&gt;&lt;p&gt;Maybe you  are yet supirsed at why more and more enterprises, like IBM, Intel, Epson,  Airbus, Ericsson etc, love to deploy packet sniffer to their company's network? OK,  take a fresh coffee now, then look at the following problems, and ask yourself,  as a &lt;strong&gt;network administrator or IT manager&lt;/strong&gt;, if these issues are just what you have  met?&lt;/p&gt;Rushing from  one network problem to another every day?&lt;br /&gt;Have no way to judge if your network has been intruded?&lt;br /&gt;Helpless  collecting convincing information to submit your boss even if you have realized  that your network system has been intruded.&lt;br /&gt;No idea  if current network usage is equal to actual need?&lt;br /&gt;Know  nothing of how many staffs are not killing their time by chatting with friends,  browsing irrelevant webpage etc, but focusing on their job?  &lt;br /&gt;&lt;p&gt;Yes,  every question listed above has puzzled many network administrators, but no  worry, packet sniffer can easily help you out with its strong functions,  here are &lt;a href="http://topnetworksniffers.blogspot.com/2009/05/ten-reasons-make-network-sniffers.html"&gt; ten reasons make packet sniffers an essential network tools.&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt; * &lt;strong&gt;Analyze network problems&lt;br /&gt;* Detect network intrusion attempts&lt;br /&gt;* Gain information for effecting a network intrusion&lt;br /&gt;* Monitor network usage&lt;br /&gt;* Gather and report network statistics&lt;br /&gt;* Filter suspect content from &lt;a href="http://blog.colasoft.com/how-to-monitor-internet-traffic-with-colasoft-packet-sniffer/"&gt;network traffic&lt;/a&gt;&lt;br /&gt;* Spy on other network users and collect sensitive information such as passwords (depending on any content encryption  methods which may be in use)&lt;br /&gt;* Reverse engineer proprietary protocols used over the network&lt;br /&gt;* Debug client/server communications&lt;br /&gt;* Debug network protocol implementations&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Currently,  there are dozens of packet sniffers in the market, some are very complex to use like  wireshark, you must be versed in networking,; some are designed for common  network administrators, such as  &lt;a href="http://www.colasoft.com/?prid=03060003"&gt;Colasoft Network Analyzer&lt;/a&gt;, &lt;strong&gt;all-in-one &amp;amp; easy-to-use&lt;/strong&gt;, which are more and more accepted and welcome.&lt;/p&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-9216063719614277952?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/9216063719614277952/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/05/ten-reasons-make-packet-sniffers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/9216063719614277952'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/9216063719614277952'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/05/ten-reasons-make-packet-sniffers.html' title='Ten Reasons Make Packet Sniffers an Essential Network Tool'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_LCrZaQE-Vo8/SgvWOTAmB7I/AAAAAAAAFDc/eVCt2TNJuZ4/s72-c/Colasoft_Capsa___Expert_Packet_Sniffer_14559.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-9052398282330500560</id><published>2009-05-13T22:06:00.000-07:00</published><updated>2009-05-13T22:20:34.929-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer'/><category scheme='http://www.blogger.com/atom/ns#' term='ettercap'/><category scheme='http://www.blogger.com/atom/ns#' term='etherdetect'/><category scheme='http://www.blogger.com/atom/ns#' term='tcpdump'/><category scheme='http://www.blogger.com/atom/ns#' term='wireshark'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>Top 5 Most Welcomed Packet Sniffers</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/?prid=00060003"&gt;&lt;img src="http://2.bp.blogspot.com/_LCrZaQE-Vo8/Sgkdrmb0U_I/AAAAAAAAFDU/W8wR_Whi8cY/s320/Colasoft+packet+sniffer+Top+5.jpg" alt="Colasoft Network Analyzer" name="Colasoft Network Analyzer" border="0" id="Colasoft Network Analyzer" style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 300px; height: 300px;" /&gt;&lt;/a&gt;According to the latest statistic from  famous download sites regarding to downloads of packet sniffer softwares, the following  products are very honored to be listed as top 5 most welcome packet sniffers by network  engineers, IT managers, and network administrators etc.&lt;br /&gt;&lt;p&gt;&lt;strong&gt;#1 Wireshark - A Free Open Source Network  Sniffer for Top Network Engineers &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Wireshark (known as Ethereal until a  trademark dispute in Summer 2006) is a fantastic open source network protocol  analyzer for Unix and Windows. It allows you to examine data from a live  network or from a capture file on disk. You can interactively browse the  capture data, delving down into just the level of packet detail you need.  Wireshark has several powerful features, including a rich display filter  language and the ability to view the reconstructed stream of a TCP session. It  also supports hundreds of protocols and media types. A tcpdump-like console  version named tethereal is included. One word of caution is that Ethereal has  suffered from dozens of remotely exploitable security holes, so stay up-to-date  and be wary of running it on untrusted or hostile networks (such as security  conferences).&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;#2 &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;Colasoft Packet Sniffer&lt;/a&gt; - All-In-One &amp;amp;  Easy-To-Use Network Analyzer and Packet Sniffers Available For Most Network Administrators.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Colasoft Packet Sniffer - Capsa&lt;/strong&gt; performs real-time packet  capturing, 24/7 network monitoring, advanced protocol analyzing, in-depth  packet decoding, and automatic expert diagnosing. It allows you to get a clear  view of the complex network, conduct packet level analysis, and troubleshoot  network problems.&lt;br /&gt;&lt;br /&gt;Whether you're a network administrator who  needs to identify, diagnose, and solve network problems, a company manager who  wants to monitor user activities on the network and ensure that the  corporation's communications assets are safe, or a consultant who has to  quickly solve network problems for clients, Capsa is the tool you need.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;#3 Tcpdump: The Classic Sniffer For Network  Monitoring And Data Acquisition&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Tcpdump is the IP sniffer we all used  before Ethereal (Wireshark) came on the scene, and many of us continue to use it frequently. It may not have the bells and whistles (such as a pretty GUI or  parsing logic for hundreds of application protocols) that Wireshark has, but it  does the job well and with fewer security holes. It also requires fewer system  resources. While it doesn't receive new features often, it is actively  maintained to fix bugs and portability problems. It is great for tracking down  network problems or monitoring activity. There is a separate Windows port named  WinDump. TCPDump is the source of the Libpcap/WinPcap packet capture library,  which is used by Nmap among many other tools.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;#4 Etherdetect : Connection-Oriented Packet  Sniffer And Protocol Analyzer&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;EtherDetect Packet Sniffer is an easy for  use and award-winning packet sniffer and network protocol analyzer, which provides a connection-oriented view for analyzing packets more effectively.  With the handy tool, all you need to do is to set up the filter, start  capturing, and view connections, packets as well as data on the fly.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;#5 Ettercap : In Case You Still Thought  Switched Lans Provide Much Extra Security&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Ettercap is a terminal-based network  sniffer/interceptor/logger for ethernet LANs. It supports active and passive dissection of many protocols (even ciphered ones, like ssh and https). Data  injection in an established connection and filtering on the fly is also  possible, keeping the connection synchronized. Many sniffing modes were  implemented to give you a powerful and complete sniffing suite. Plugins are  supported. It has the ability to check whether you are in a switched LAN or  not, and to use OS fingerprints (active or passive) to let you know the  geometry of the LAN.&lt;/p&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-9052398282330500560?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/9052398282330500560/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/05/top-5-most-welcomed-packet-sniffers.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/9052398282330500560'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/9052398282330500560'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/05/top-5-most-welcomed-packet-sniffers.html' title='Top 5 Most Welcomed Packet Sniffers'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LCrZaQE-Vo8/Sgkdrmb0U_I/AAAAAAAAFDU/W8wR_Whi8cY/s72-c/Colasoft+packet+sniffer+Top+5.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-4499217538877155228</id><published>2009-05-11T23:58:00.000-07:00</published><updated>2009-05-12T00:27:15.170-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MAC address'/><category scheme='http://www.blogger.com/atom/ns#' term='howto'/><category scheme='http://www.blogger.com/atom/ns#' term='Colasoft MAC Scanner'/><title type='text'>How to Find MAC Address with Colasoft MAC Scanner and More</title><content type='html'>&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/05/colasoft-mac-scanner-screenshot.jpg"&gt;&lt;img title="Colasoft MAC Scanner Screenshot" src="http://blog.colasoft.com/wp-content/uploads/2009/05/colasoft-mac-scanner-screenshot.jpg" alt="Colasoft MAC Scanner Screenshot" align="left" height="229" width="289" /&gt;&lt;/a&gt;In computer networking, a Media Access Control address (&lt;strong&gt;MAC address&lt;/strong&gt;) is a &lt;strong&gt;unique&lt;/strong&gt; identifier assigned to most network adapters or network interface cards (NICs) by the manufacturer for identification, and used in the Media Access Control protocol sublayer. If assigned by the manufacturer, a MAC address usually encodes the manufacturer's registered identification number. It may also be known as an Ethernet Hardware Address (EHA), hardware address, adapter address, or physical address.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Since a MAC Address is unique for most network adapters or network interface cards (NICs), it is important for IT administrators to know all the MAC addresses in LAN so as to quickly locate a network device when a network issue arises. Luckily we have tools to help us out. Let’s see how we can easily &lt;a href="http://blog.colasoft.com/how-to-find-mac-address-with-colasoft-mac-scanner-and-more/"&gt;find MAC address&lt;/a&gt; in LAN with Colasoft MAC Scanner.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Colasoft MAC Scanner is a &lt;strong&gt;Free&lt;/strong&gt; software to find MAC address and IP address. It can automatically detect all subnets according to the IP addresses configured on multiple NICs of a machine and find MAC addresses and IP addresses of defined subnets as your need. Users can custom own scan process by specifying the subsequent threads.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Step 1. &lt;a title="download Colasoft MAC Scanner" href="http://www.colasoft.com/mac_scanner/?prid=csblog" target="_blank"&gt;Download Colasoft MAC Scanner&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Step2. Install Colasoft MAC Scanner&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The installation of Colasoft MAC Scanner is quick and easy, it is suggested to install Colasoft MAC Scanner on a laptop as it only scans and finds MAC addresses and IP addresses in the subnet to which the laptop is connected.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Step3. Start a Scan&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;It’s easy and quick, just press the start button, the Colasoft MAC Scanner will scan and find MAC addresses and IP addresses in the subnet and list them out. The results can be “copy and paste” or exported for future reference.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Now the problem is: if a LAN is divided into several subnets, we’ll have to move the laptop around and scan each subnet in order to find all MAC addresses and IP addresses. Then what’s the solution?&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Find MAC Address and IP Address with &lt;a title="Colasoft Packet Sniffer" href="http://www.colasoft.com/capsa/?prid=csblog" target="_blank"&gt;Colasoft Packet Sniffer&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Colasoft Packet Sniffer allows us to find MAC addresses and IP addresses both local and remote in the network as long as there is network communication initiated.&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: center;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/05/colasoft-packet-sniffer-mac.jpg"&gt;&lt;img style="vertical-align: middle;" title="Find MAC Address in Colasoft Packet Sniffer" src="http://blog.colasoft.com/wp-content/uploads/2009/05/colasoft-packet-sniffer-mac.jpg" alt="Find MAC Address in Colasoft Packet Sniffer" align="" height="413" width="470" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&gt;&gt;&gt;&gt;&lt;a title="Download Colasoft Packet Sniffer" href="http://www.colasoft.com/colasoft.com/download/products/download_capsa.php?prid=csblog" target="_blank"&gt;Download Colasoft Packet Sniffer Now&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-4499217538877155228?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/4499217538877155228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/05/how-to-find-mac-address-with-colasoft.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/4499217538877155228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/4499217538877155228'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/05/how-to-find-mac-address-with-colasoft.html' title='How to Find MAC Address with Colasoft MAC Scanner and More'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-18562056891998259</id><published>2009-05-11T01:49:00.000-07:00</published><updated>2009-05-11T02:13:46.953-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='performance'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='protocol'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Find Out the Top Network Administrator Tools</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/capsa/?prid=00060003"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 213px;" src="http://2.bp.blogspot.com/_LCrZaQE-Vo8/SgPa7EgEWgI/AAAAAAAAFDE/OBE1N0_RO_U/s320/colasoft+network+analyzer.jpg" alt="" id="BLOGGER_PHOTO_ID_5333347092092180994" border="0" /&gt;&lt;/a&gt;&lt;strong&gt;Packet Sniffers/Network Protocol Analyzer&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;With packet sniffers and network protocol analyzers, you can monitor network activity, analyze network performance, enhance  network security, and troubleshoot network issues.&lt;/p&gt;&lt;span&gt;1,&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;Colasoft Packet Sniffer&lt;/a&gt; - &lt;/span&gt; &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;http://www.colasoft.com/&lt;/a&gt; Colasoft Capsa performs real-time packet capturing, 24/7 network monitoring, advanced protocol analyzing, in-depth packet decoding, and automatic expert diagnosing. It allows you to get a clear view of the complex network, conduct packet level analysis, and troubleshoot network problems.&lt;br /&gt;2, Ethereal   – http://www.ethereal.com/&lt;br /&gt;3, EtterCap – http://ettercap.sourceforge.net/&lt;br /&gt;4, Snort   – http://www.snort.org/&lt;br /&gt;5, WinDump / TCPDump - http://www.tcpdump.org/wpcap.html/&lt;br /&gt;6, DSniff   – http://naughty.monkey.org/~dugsong/dsniff/&lt;p&gt;&lt;strong&gt;Scanning  Tools&lt;/strong&gt;&lt;br /&gt;1, Nmap   – http://www.nmap.org/&lt;br /&gt;Nmap is a port scanner. A port scanner  scans for open ports, such as 80 (http) or 25 (SMTP)&lt;br /&gt;&lt;/p&gt;&lt;p&gt;2, Sam Spade – www.samspade.org/&lt;br /&gt;Sam Spade is a multi network query tool  with many extra built in utilities, even a tool for spam. It includes utilities  such as ping, whois, traceroute, and finger&lt;br /&gt;&lt;br /&gt;3, NetScanTools Pro ($199) –http://www.netscantools.com/nstmain.html&lt;br /&gt;NetScanTools Pro Edition is an integrated  collection of internet information gathering utilities for Windows  Vista/2008/2003/XP/2000. Use it to research IP addresses, hostnames, domain  names, email addresses, URLs automatically** or with manual tools.&lt;br /&gt;&lt;br /&gt;4, SuperScan   – http://www.foundstone.com/&lt;br /&gt;SuperScan has the primary purpose of  scanning an IP range. It supports extremely fast Host Discovery lookups as well  as TCP and UDP port scans thanks to its multi-threaded and asynchronous  techniques.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;UserManagement   - http://www.tools4ever.com&lt;/strong&gt;/&lt;br /&gt;Complete user account management featuring  advanced user creation, modification, removal, mass creation/removal and  delegation of administrative tasks. The UserManagemeNT Suite consists of three  modules, Professional, Import and Delegation. These modules can operate  independently or seamlessly integrated with each other.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;AdminMagic  - http://www.tools4ever.com&lt;/strong&gt;/&lt;br /&gt;Full control: Using AdminMagic, you can  take over and control users' desktops from your own workstation. Featuring  complete mouse and keyboard emulation, you can execute programs, login/logoff,  modify device drivers and reboot all from a central location. You can also take  screenshots of remote desktops and store/print them for later use. Remote users  will not be interrupted and can continue working as they always do.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Advanced System Optimizer&lt;/strong&gt; - http://www.systweak.com/&lt;br /&gt;Advanced System Optimizer is a system  tweaking suite that includes around 30 tools to improve and tweak your PC's  performance. It offers an attractive and easy to use interface that organizes  all tasks into categories and provides graphical statistics whenever possible.  The tools include junk file cleaner, memory optimizer, system information,  system files backup, file encryption, safe uninstaller, duplicate file finder,  taskbar manager and much more. Advanced System Optimizer also includes an  Internet tracks eraser with cookie manager and secure deletion, and even a  desktop sticky notes application. Overall, a great bundle that offers a wide  range of system tools with extra benefits that are hardly ever found.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-18562056891998259?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/18562056891998259/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/05/find-out-top-network-administrator.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/18562056891998259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/18562056891998259'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/05/find-out-top-network-administrator.html' title='Find Out the Top Network Administrator Tools'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LCrZaQE-Vo8/SgPa7EgEWgI/AAAAAAAAFDE/OBE1N0_RO_U/s72-c/colasoft+network+analyzer.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-7250019543187645739</id><published>2009-05-07T00:08:00.000-07:00</published><updated>2009-05-07T00:20:13.705-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer'/><category scheme='http://www.blogger.com/atom/ns#' term='Public Key Encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='Email Privacy'/><title type='text'>How Public Key Encryption Can Make Email More Private</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_LCrZaQE-Vo8/SgKFANEmBlI/AAAAAAAAFC8/0lfM82JogFk/s1600-h/colasoft+network+sniffer+3.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 211px;" src="http://3.bp.blogspot.com/_LCrZaQE-Vo8/SgKFANEmBlI/AAAAAAAAFC8/0lfM82JogFk/s320/colasoft+network+sniffer+3.jpg" alt="colasoft packet sniffer" id="BLOGGER_PHOTO_ID_5332971147315512914" border="0" /&gt;&lt;/a&gt;When you are entering your credit  card number, talking with your lover, chatting with your business partners, can you imagine what will happen if everything you are doing is exposing to everybody?&lt;br /&gt;&lt;p&gt; Yes, it is unbelievable but it is quite true, hackers can easily obtain your private information like crecit card number, email logs, chat logs  etc. by using some network analytic tools, such as &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;Colasoft Packet Sniffer&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Protect Your Email Secure And Safe&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;So if we are helpless with our private  information from being monitored or stolen? Of course not, to keep data sent  via email private, you just need to encrypt it, as only unencrypted content can  be monitored by network analytic tools like &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;Network Analyzer&lt;/a&gt;. Only the targeted  recipient will be able to decipher the message.  &lt;/p&gt;&lt;p&gt;&lt;strong&gt;How to Encrypt Your Message?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Public key  encryption is a special case of encryption, it operates using a combination of  two keys: one is a private key, the other is a public key which together form a  pair of keys. The private key is kept secret on your computer since it  is used for decryption, the public key, which is used for encryption, is  given to anybody who wants to send encrypted mail to you. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;How Public Key works?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;When you  send public-key encrypted mail, the sender's encryption  program uses your public key in combination with the sender's private key to  encipher the message. When you  receive public-key encrypted mail, you need to decipher  it.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_LCrZaQE-Vo8/SgKDDsVOfxI/AAAAAAAAFC0/5K455Z_NpyE/s1600-h/colasoft+network+sniffer+2.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 234px; height: 320px;" src="http://1.bp.blogspot.com/_LCrZaQE-Vo8/SgKDDsVOfxI/AAAAAAAAFC0/5K455Z_NpyE/s320/colasoft+network+sniffer+2.jpg" alt="colasoft packet sniffer" id="BLOGGER_PHOTO_ID_5332969008223125266" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Decryption of a message enciphered with a  public key can only be done with the matching private key. This is why the two  keys form a pair, and it is also why it is so important to keep the private key  safe and to make sure it never gets into the wrong hands (or in any hands other  than yours). &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Why the Integrity of the Public Key is  Essential&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Another crucial point with public key  encryption is the distribution of the public key.&lt;br /&gt;Public key encryption is only safe and  secure if the sender of an enciphered message can be sure that the public key  used for encryption belongs to the recipient.&lt;br /&gt;A third party can produce a public key with  the recipient's name and give it to the sender, who uses the key to send important  information in encrypted form. The enciphered message is intercepted by the  third party, and since it was produced using their public key they have no  problem deciphering it with their private key.&lt;br /&gt;This is why it is mandatory that a public  key is either given to you personally or authorized by a certificate authority. &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-7250019543187645739?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/7250019543187645739/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/05/how-public-key-encryption-can-make.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/7250019543187645739'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/7250019543187645739'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/05/how-public-key-encryption-can-make.html' title='How Public Key Encryption Can Make Email More Private'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LCrZaQE-Vo8/SgKFANEmBlI/AAAAAAAAFC8/0lfM82JogFk/s72-c/colasoft+network+sniffer+3.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-2067252748140761740</id><published>2009-05-06T02:56:00.000-07:00</published><updated>2009-05-06T03:02:09.380-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer'/><category scheme='http://www.blogger.com/atom/ns#' term='monitor'/><category scheme='http://www.blogger.com/atom/ns#' term='traffic'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><title type='text'>Monitor Your Network Traffic with Colasoft Packet Sniffer</title><content type='html'>&lt;strong&gt;Importance of Network Monitoring&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;Reading network traffic is essential for system administrators, network engineers, and security analysts. At some point there will be a need to read the network traffic directly instead of monitoring application level details. Examples of situations that might require monitoring network traffic are, auditing network security, debugging network configurations, and analyzing usage patterns. For this task we use network monitoring software, or packet sniffers, that sniff the traffic your computer is able to see on the network. What exactly your computer can see really depends on how the network is laid out, but the easiest way to figure out what it can see is just start sniffing.&lt;br /&gt;&lt;br /&gt;The most common tool to do the job is readily available. One of the most popular and easy – to - use tool for monitoring network traffic is &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;Colasoft Packet Sniffer&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;&lt;strong&gt;How to Monitor Network Traffic &lt;/strong&gt;&lt;br /&gt;&lt;p&gt;As a packet sniffer, &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;Capsa&lt;/a&gt; make it easy for us to monitor and analyze network traffic in its  intuitive and information-rich tab views. With Capsa's network traffic monitor  feature, we can quickly identify network bottleneck and detect network  abnormities. This article is to discuss how we can Monitor Network Traffic with  Capsa's network traffic monitor feature.&lt;/p&gt;&lt;br /&gt;     &lt;strong&gt;1, Monitor Network Traffic in "Summary"     &lt;/strong&gt;&lt;br /&gt;     &lt;strong&gt;tab     &lt;/strong&gt;&lt;br /&gt;     &lt;p&gt;"Summary" is a view that provides general information of the  entire network or the selected node in the "Explorer". In  "Summary" we can get a quick view of the total traffic, real-time  traffic, broadcast traffic, multicast traffic and so on. When we switch among  the node from the explorer, corresponding traffic information will be provided.&lt;/p&gt;     &lt;p&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic6.gif" alt="Monitor Network Traffic in Summary" height="481" width="574" /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;(pic 1. monitor-network-traffic-in-summary)&lt;br /&gt;&lt;/p&gt;     &lt;br /&gt;&lt;strong&gt;2, Monitor Network Traffic in "Endpoints" tab&lt;/strong&gt;&lt;br /&gt;                   &lt;p&gt;In "Endpoints" view, we can Monitor Network Traffic  information of each node, both local and remote. With its easy sorting feature  we can easily find out which host is generating or has generated the largest  traffic.&lt;/p&gt;     &lt;p&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic1.gif" alt="Monitor Network Traffic in Endpoints" height="481" width="574" /&gt;&lt;/p&gt;     &lt;p&gt;(pic 2. monitor-network-traffic-in-endpoints)&lt;/p&gt;     &lt;br /&gt;                   &lt;strong&gt;3, Monitor Network Traffic in "Protocols" tab&lt;/strong&gt;&lt;br /&gt;     &lt;p&gt;"Protocols" view will list all protocols applied in network  transmission. In "Protocols" view we can Monitor Network Traffic by each protocol. By analyzing network traffic by protocol, we can understand what  applications are using the network bandwidth, for example "http"  protocol stands for website browsing, "pop3" stands for email, etc.&lt;/p&gt;     &lt;p&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic2.gif" alt="Monitor Network Traffic by Protocol" height="481" width="574" /&gt;&lt;/p&gt;     &lt;p&gt;(pic 3. monitor-network-traffic-by-protocol)&lt;/p&gt;     &lt;br /&gt;     &lt;strong&gt;4, Monitor Network Traffic in "Conversations" tab&lt;/strong&gt;&lt;br /&gt;     &lt;p&gt;In "Conversations" tab we can Monitor Network Traffic by  each conversation and the figure out which conversation has generated the  largest network traffic.&lt;/p&gt;     &lt;p&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic3.gif" alt="Monitor Network Traffic by Conversation" height="481" width="575" /&gt;&lt;/p&gt;     &lt;p&gt;(pic 4. monitor-network-traffic-by-conversation)&lt;/p&gt;     &lt;br /&gt;     &lt;strong&gt;5, Monitor Network Traffic in "Matrix" tab&lt;/strong&gt;&lt;br /&gt;     &lt;p&gt;"Matrix" is a view that visualizes all network connections  and traffic details in one single graph. The weight of the lines between the nodes indicates the traffic volume  and the color indicates the status. As we move the cursor on a specific node,  network traffic details of the node will be provided.&lt;/p&gt;     &lt;p&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic4.gif" alt="Monitor Network Traffic In Matrix" height="481" width="574" /&gt;&lt;/p&gt;(pic 5. monitor-network-traffic-in-Matrix)&lt;br /&gt;     &lt;strong&gt;&lt;br /&gt;6,Monitor Network Traffic in "Graphs" tab&lt;/strong&gt;&lt;br /&gt;     &lt;p&gt;If we want to get a trend chart of the network traffic, then we need  to use the "Graphs" tab. "Graphs" view allows us view  network statistics dynamically in different chart types, such as ling chart, bar  chart, and pie chart. By selecting "Utilization" we get a real-time  traffic trend chart.&lt;/p&gt;     &lt;p&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic5.gif" alt="Monitor Network Traffic in Graphs" height="481" width="574" /&gt;&lt;/p&gt;(pic 6. monitor-network-traffic-in-graphs)&lt;br /&gt;     &lt;p&gt;As we can see, with &lt;a href="http://www.colasoft.com/download/?prid=00060003"&gt;Capsa&lt;/a&gt; we can not only Monitor Network Traffic in  convenience, but also analyze network traffic in deferent levels, thus enables  us quickly and efficiently detect network abnormities and troubleshoot network  problems. &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-2067252748140761740?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/2067252748140761740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/05/monitor-your-network-traffic-with.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/2067252748140761740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/2067252748140761740'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/05/monitor-your-network-traffic-with.html' title='Monitor Your Network Traffic with Colasoft Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-330128427520298520</id><published>2009-05-04T23:28:00.000-07:00</published><updated>2009-05-04T23:38:36.157-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kismet'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer article'/><title type='text'>Kismet, an 802.11 Layer2 Wireless Network Detector and Packet Sniffer</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;a href="http://packetsniffer.blog.com/files/2009/05/kismet1.png"&gt;&lt;img title="Kismet Screeshot" src="http://packetsniffer.blog.com/files/2009/05/kismet1-300x210.png" alt="Kismet Screeshot" align="right" height="210" width="300" /&gt;&lt;/a&gt;&lt;strong&gt;What is Kismet&lt;/strong&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;Kismet is an 802.11 layer2 wireless network detector, &lt;a title="Colasoft packet sniffer" href="http://www.colasoft.com/capsa/?prid=00060001" target="_blank"&gt;packet sniffer&lt;/a&gt;, and intrusion detection system.  Kismet will work with any wireless card which supports raw monitoring (rfmon) mode, and can sniff 802.11b, 802.11a, 802.11n, and 802.11g traffic (devices and drivers permitting). Kismet identifies networks by passively collecting packets and detecting standard named networks, detecting (and given time, decloaking) hidden networks, and inferring the presence of non-beaconing networks via data traffic.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Feature Overview&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Kismet has many features useful in different situations for monitoring wireless networks:&lt;br /&gt;&lt;br /&gt;- Ethereal/Tcpdump compatible data logging&lt;br /&gt;- Airsnort compatible weak-iv packet logging&lt;br /&gt;- Network IP range detection&lt;br /&gt;- Built-in channel hopping and multicard split channel hopping&lt;br /&gt;- Hidden network SSID decloaking&lt;br /&gt;- Graphical mapping of networks&lt;br /&gt;- Client/Server architecture allows multiple clients to view a single Kismet server simultaneously&lt;br /&gt;- Manufacturer and model identification of access points and clients&lt;br /&gt;- Detection of known default access point configurations&lt;br /&gt;- Runtime decoding of WEP packets for known networks&lt;br /&gt;- Named pipe output for integration with other tools, such as a layer3 IDS like Snort&lt;br /&gt;- Multiplexing of multiple simultaneous capture sources on a single Kismet instance&lt;br /&gt;- Distributed remote drone sniffing&lt;br /&gt;- XML output&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Typical Uses&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Common applications Kismet is useful for:&lt;br /&gt;&lt;br /&gt;- Wardriving:  Mobile detection of wireless networks, logging and mapping of network location, WEP, etc.&lt;br /&gt;- Site survey:  Monitoring and graphing signal strength and location.&lt;br /&gt;- Distributed IDS:  Multiple Remote Drone sniffers distributed throughout an installation monitored by a single server, possibly combined with a layer3 IDS like Snort.&lt;br /&gt;- Rogue AP Detection:  Stationary or mobile sniffers to enforce site policy against rogue access points.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Download&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Kismet can be downloaded &lt;a title="Kismet download" href="http://www.kismetwireless.net/download.shtml" target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;/p&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-330128427520298520?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/330128427520298520/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/05/kismet-80211-layer2-wireless-network.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/330128427520298520'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/330128427520298520'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/05/kismet-80211-layer2-wireless-network.html' title='Kismet, an 802.11 Layer2 Wireless Network Detector and Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-7447173837602683007</id><published>2009-04-27T22:45:00.000-07:00</published><updated>2009-04-27T22:50:35.387-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='traffic'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer howto'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='monitor traffic'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>How to Monitor Internet Traffic with Packet Sniffer</title><content type='html'>Internet traffic is the flow of data around the Internet. It includes web traffic, which is the amount of that data that is related to the World Wide Web, along with the traffic from other major uses of the Internet, such as electronic mail and peer-to-peer networks.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;In case we want to &lt;strong&gt;monitor internet traffic&lt;/strong&gt; generated or is generating in LAN, here is a detailed process how we can do it with &lt;a title="Colasoft Packet Sniffer Software" href="http://www.colasoft.com/?prid=00060001" target="_blank"&gt;Colasoft Packet Sniffer&lt;/a&gt; – Capsa.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Again we must make sure the packet sniffer software is correctly implemented so we can capture all the traffic in LAN, if you don’t know how to do it, please make sure you read &lt;a title="How to Implement a Packet Sniffer" href="http://www.colasoft.com//support/installation.php?prid=00060001" target="_blank"&gt;how to implement a packet sniffer&lt;/a&gt;.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;First let’s launch a new project with Colasoft Packet Sniffer, then do some online activities, such as chatting, browsing a website, sending and receiving emails, downloading some files. All these activities will generate different kinds of internet traffic. We may keep the project running to continuously &lt;a title="How to Monitor Internet Traffic with Colasoft Packet Sniffer" href="http://blog.colasoft.com/how-to-monitor-internet-traffic-with-colasoft-packet-sniffer/" target="_self"&gt;monitor internet traffic&lt;/a&gt; or stop the project to do some analysis.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;To monitor internet traffic, we’d better first select the “Internet Addresses” in the “Explorer” on the left window:&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-internet-traffic-ss1.jpg"&gt;&lt;img class="size-full wp-image-78" title="Monitor Internet Traffic Screenshot1" src="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-internet-traffic-ss1.jpg" alt="Monitor Internet Traffic Screenshot1" width="485" height="375" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;We can see that all the internet addresses are listed by countries, to monitor internet traffic of a specific country, we just need click on it; If we want to monitor internet traffic of a specific IP address within one country, we need to expand the country node and select the IP address in it.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Also we can monitor internet traffic aggregated or internet traffic in real-time&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-internet-traffic-ss2.jpg"&gt;&lt;img class="size-full wp-image-79" title="Monitor Internet Traffic Screenshot2" src="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-internet-traffic-ss2.jpg" alt="Monitor Internet Traffic Screenshot2" width="463" height="350" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;To view what online activities have generated or are generating internet traffic, we need to use the “Protocols” Tab.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-internet-traffic-ss3.jpg"&gt;&lt;img class="size-full wp-image-80" title="Monitor Internet Traffic Screenshot1" src="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-internet-traffic-ss3.jpg" alt="Monitor Internet Traffic Screenshot1" width="506" height="364" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;We can see there are protocols which separately stand for different internet activities:&lt;br /&gt;&lt;p&gt;&lt;br /&gt;HTTP – Website browsing&lt;br&gt;&lt;br /&gt;MSN – online chatting with Live Messenger&lt;br&gt;&lt;br /&gt;POP3 – Email&lt;br&gt;&lt;br /&gt;HTTPS - Website browsing via a secure link&lt;br&gt;&lt;br /&gt;QQ- online chatting with QQ&lt;br&gt;&lt;br /&gt;DNS – Domain Name System&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;About Capsa&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Colasoft Capsa is a network analyzer (packet sniffer or protocol analyzer) designed for network monitoring and troubleshooting. It performs packet capturing, network monitoring, protocol analyzing, packet decoding, and automatic diagnosing. By giving users insights into all of network's operations, Capsa makes it easy to isolate and solve network problems, identify network bottleneck and bandwidth use, and detect network vulnerabilities. Learn more about Capsa, please visit &lt;a href="http://www.colasoft.com/capsa/?prid=00060001"&gt;http://www.colasoft.com/capsa/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-7447173837602683007?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/7447173837602683007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/how-to-monitor-internet-traffic-with.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/7447173837602683007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/7447173837602683007'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/how-to-monitor-internet-traffic-with.html' title='How to Monitor Internet Traffic with Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-8418720900685824172</id><published>2009-04-23T00:55:00.000-07:00</published><updated>2009-04-23T01:01:38.566-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer article'/><title type='text'>What Can Hackers Do with a Packet Sniffer</title><content type='html'>&lt;h2&gt;What Can Hackers Do with a Packet Sniffer?&lt;/h2&gt;&lt;b&gt;A &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;packet sniffer&lt;/a&gt; in the wrong hands is a deadly weapon. A packet sniffer is a real danger because it is&lt;/b&gt;&lt;b&gt; a very powerful and difficult to detect tool&lt;/b&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/capsa/?prid=00060003"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 300px; height: 300px;" src="http://3.bp.blogspot.com/_LCrZaQE-Vo8/SfAAs03FnUI/AAAAAAAAFB8/H-Ql0ykZDj4/s320/hacker.gif" alt="colasoft packet sniffer" id="BLOGGER_PHOTO_ID_5327759129283239234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Security breaches of all kinds are reported all the time. Everyday we hear of hackers who managed to steal sensitive data, of people who become victims of identity theft, etc. Very  often the breaches are so incredible that you wonder if hackers have supernatural powers. Well, hackers hardly have supernatural powers but they don't need them –supernatural powers are not necessary when a networklacks security and one has the right tools to break in.&lt;br /&gt;&lt;h2&gt;Hackers Can Monitor Networks With a Packet Sniffer&lt;/h2&gt;&lt;strong&gt;The tools hackers use to break into networks are more or les&lt;/strong&gt;&lt;strong&gt;s the same tools network admins use to monitor and maintain their network with&lt;/strong&gt;. For example, packet sniffers are among the tools hackers love most. A packet sniffer captures packets and shows you their contents.This means that with the help of a packet sniffer running somewhere into the network, hackers can monitor all the unencrypted traffic to and from this network.&lt;br /&gt;&lt;p&gt;This is really scary – just imagine a malicious hacker who knows all the secrets of your company. It gets even more dangerous for networks, where hubs (and not switches) are used because in this case a packet sniffer can be installed on any computer and the hacker will monitor all the traffic in that segment, not only the traffic to and from the host. The good news is that hubs are almost out of use today and because of that hackers can do less damage with a packet sniffer. &lt;/p&gt;&lt;h2&gt;Hackers Can Obtain Passwords and Credit Card Numbers With a Packet Sniffer&lt;/h2&gt;When a hacker uses a packet sniffer to monitor your network, this is not nice but when he or she steals passwords, credit card numbers and other types of sensitive data, this is a real danger. Unencrypted passwords, credit card numbers and other sensitive data are an easy target for a hacker with a packet sniffer.&lt;br /&gt;&lt;p&gt;In many of the cases of mass theft of credit card numbers and passwords happen because hackers use a packet sniffer on an unencrypted network. For truth's sake, it is important to mention that even if all the traffic is encrypted, there are still many other ways to obtain sensitive data. But when the traffic over a network is not encrypted and nobody monitors the network for unauthorized packet sniffers, sooner or later data will be stolen.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;One of the greatest achievements for hackers with a packet sniffer is to capture the administrator's password. When the administrator's password is transmitted over the network in an unencrypted form, this is an easy target for hackers. If hackers manage to intercept the admin password, they have the power to do everything they want to on your network – delete data, modify data, etc. So, do you see why hackers don't need supernatural powers but only the admin password?&lt;/p&gt;&lt;br /&gt;&lt;P&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;About Colasoft&lt;/b&gt;&lt;br&gt;&lt;br /&gt;Ever since 2001, Colasoft has been an innovative provider of all-in-one and easy-to-use &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;network analyzer software&lt;/a&gt; for network administrators and IT managers to monitor network activities, analyze network performance, enhance network security, and troubleshoot network problems. Up to now, more than 5000 customers in over 70 countries trust the flagship product – Capsa as their network monitoring and troubleshooting solution. Colasoft also offers four &lt;b&gt;free network utilities&lt;/b&gt;: Colasoft Packet Builder, Colasoft Packet Player, Colasoft MAC Scanner, and Colasoft Ping Tool. Learn more about Colasoft and its solutions, please visit http://www.colasoft.com/.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-8418720900685824172?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/8418720900685824172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/what-can-hackers-do-with-packet-sniffer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8418720900685824172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8418720900685824172'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/what-can-hackers-do-with-packet-sniffer.html' title='What Can Hackers Do with a Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LCrZaQE-Vo8/SfAAs03FnUI/AAAAAAAAFB8/H-Ql0ykZDj4/s72-c/hacker.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-1867768468245942010</id><published>2009-04-23T00:12:00.000-07:00</published><updated>2009-04-23T20:28:05.769-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='http'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer howto'/><category scheme='http://www.blogger.com/atom/ns#' term='monitor traffic'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>How to Monitor http Traffic with Packet Sniffer</title><content type='html'>Hypertext Transfer Protocol (&lt;strong&gt;HTTP&lt;/strong&gt;) is an application-level protocol for distributed, collaborative, hypermedia information systems. Its use for retrieving inter-linked resources led to the establishment of the World Wide Web.&lt;br /&gt;&lt;P&gt;&lt;br /&gt;In order to &lt;strong&gt;monitor http traffic&lt;/strong&gt;, we will need a packet sniffer (or a protocol analyzer) software. Here is a detail process how we can &lt;a href="http://blog.colasoft.com/how-to-monitor-http-traffic-with-packet-sniffer/?prid=00060001"&gt;monitor http traffic&lt;/a&gt; in LAN with &lt;a title="Colasoft Packet Sniffer Software" href="http://www.colasoft.com/capsa/?prid=00060001" target="_blank"&gt;Colasoft Packet Sniffer&lt;/a&gt; – Capsa.&lt;br /&gt;&lt;P&gt;&lt;br /&gt;Again let’s launch Colasoft Packet Sniffer and start a new project. Don’t forget one thing, we have to deploy the packet sniffer to the mirror port of the core switch in order to monitor all http traffic in LAN, if not, we can only monitor http traffic of our own computer.&lt;br /&gt;&lt;P&gt;&lt;br /&gt;Then let’s start browsing a website, for example, www.colasoft.com, to generate some http traffic. Now let’s get back to the packet sniffer and see if there is http traffic. OK, we can see the packet sniffer has already captured some http traffic in the “&lt;strong&gt;Protocols&lt;/strong&gt;” Tab&lt;br /&gt;&lt;P&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-http-traffic1.jpg"&gt;&lt;img class="size-full wp-image-69" title="monitor-http-traffic1" src="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-http-traffic1.jpg" alt="Monitor http Traffic Screenshot 1" width="544" height="405" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;P&gt;&lt;br /&gt;We can see both the &lt;strong&gt;aggregated http traffic&lt;/strong&gt; since start capturing and the &lt;strong&gt;real-time http traffic&lt;/strong&gt; in this tab.&lt;br /&gt;&lt;P&gt;&lt;br /&gt;If we want to do a deeper analysis on http traffic, we will need to use the “&lt;strong&gt;Locate&lt;/strong&gt;” function to locate http protocol in the Explorer to let the packet sniffer display only the data that is http protocol. Right click on the protocol and select “Locate Explorer Node” in the pop-up menu.&lt;br /&gt;&lt;P&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-http-traffic2.jpg"&gt;&lt;img class="size-full wp-image-70" title="Monitor Http Traffic Screenshot 2" src="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-http-traffic2.jpg" alt="Locate Explorer Node" width="221" height="292" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;P&gt;&lt;br /&gt;If we want to know who are using http protocol and what they are actually browsing, we are going to use two tabs, the “Endpoints” Tab and “Logs” Tab.&lt;br /&gt;&lt;P&gt;&lt;br /&gt;Let’s see who are using http protocol:&lt;br /&gt;&lt;P&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-http-traffic3.jpg"&gt;&lt;img class="size-full wp-image-71" title="Monitor http Traffic Screenshot 3" src="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-http-traffic3.jpg" alt="Who is Using http Protocol" width="544" height="408" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;P&gt;&lt;br /&gt;And what they are actually browsing:&lt;br /&gt;&lt;P&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-http-traffic4.jpg"&gt;&lt;img class="size-full wp-image-72" title="Monitor http Traffic Screenshot 4" src="http://blog.colasoft.com/wp-content/uploads/2009/04/monitor-http-traffic4.jpg" alt="Monitor http Traffic Screenshot 4" width="544" height="408" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-1867768468245942010?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/1867768468245942010/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/how-to-monitor-http-traffic-with-packet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/1867768468245942010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/1867768468245942010'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/how-to-monitor-http-traffic-with-packet.html' title='How to Monitor http Traffic with Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-4792752130040951959</id><published>2009-04-22T00:43:00.000-07:00</published><updated>2009-04-22T00:49:08.852-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IT Management'/><title type='text'>5 Things IT Department had to skip in Recession</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_LCrZaQE-Vo8/Se6OlfQUc2I/AAAAAAAAFBM/n7C5D39fbYw/s1600-h/colasoft+network+sniffer.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 227px; height: 320px;" src="http://2.bp.blogspot.com/_LCrZaQE-Vo8/Se6OlfQUc2I/AAAAAAAAFBM/n7C5D39fbYw/s320/colasoft+network+sniffer.jpg" alt="" id="BLOGGER_PHOTO_ID_5327352183922127714" border="0" /&gt;&lt;/a&gt;In last blog, we have talked about the &lt;a href="http://snifferclub.blogspot.com/2009/04/top-5-items-it-department-must-do.html"&gt;5 items IT department must do&lt;/a&gt; even in the big recession, in addition to the things we can't do without, there are many more  things we had to skip. We are not exactly happy to stop doing these  things but desperate times cry for desperate measures and since these  activities are something we can do without we had to either quit  them, or drastically reduce them:&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;No purchases of new hardware&lt;/span&gt;. Though it is not precise to say  that we haven't bought a single piece of hardware in the last year,  we have definitely cut hardware spendings. For the time being we do  not plan to make major hardware purchases.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Capital expenditures.&lt;/span&gt; Capital expenditures are another budget  item we had to drastically shrink. We had schedules projects but the  current economic situation made us have second thoughts and now  capital expenditures are on hold.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Software that is nice to have but we can do without it&lt;/span&gt;.  Similarly to hardware and capital expenditures, some major software  expenses had to be cut. Yes, there are many products, for instance  accounting, HR, or ERP modules, which are great to have but we'll go  for them when the economic outlook is less gloomy.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Standardization&lt;/span&gt;. You know that IT people generally hate when  they have to deal with bureaucracy and standardization, so if there  is an item, we are happy to skip, this is standardization. More or  less we skipped all standardization-related activities except those,  that are related to regulations compliance. Standardization is put  on hold, especially if it requires investment or other resources.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;No infrastructure upgrades&lt;/span&gt;. We are not exactly happy about  this one but since there are more important items we can't skip, we  had to significantly reduce the planned network upgrades. Some of  the projects in this area are put on hold, while others are  canceled.    &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;It wasn't easy to decide what to skip and what to keep but when times are tough, it is not possible to pretend that everything is OK and go on as planned. We hope that we are right in our choices and time will show if we did wise choices or not.  &lt;/p&gt;&lt;p&gt;James Ackland is Author of this article from &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;www.Colasoft.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;About Colasoft Co., Ltd.&lt;br /&gt;Ever since 2001, Colasoft has been dedicated in providing all-in-one and easy-to-use packet sniffer software for network administrators and IT managers to monitor network activities, analyze network performance, enhance network security, and troubleshoot network problems. Up to now, more than 5000 customers in over 70 countries trust the flagship product – &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;Colasoft Packet Sniffer&lt;/a&gt; as their network monitoring and troubleshooting solution. Colasoft also offers four&lt;span style="font-weight: bold;"&gt; free network utilities:&lt;/span&gt; Colasoft Packet Builder, Colasoft Packet Player, Colasoft MAC Scanner, and Colasoft Ping Tool. Learn more about Colasoft and its solutions, please visit &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;http://www.colasoft.com/&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-4792752130040951959?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/4792752130040951959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/5-things-it-department-had-to-skip-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/4792752130040951959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/4792752130040951959'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/5-things-it-department-had-to-skip-in.html' title='5 Things IT Department had to skip in Recession'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LCrZaQE-Vo8/Se6OlfQUc2I/AAAAAAAAFBM/n7C5D39fbYw/s72-c/colasoft+network+sniffer.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-2099360267677333457</id><published>2009-04-19T20:13:00.000-07:00</published><updated>2009-04-19T23:24:28.895-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Management'/><title type='text'>Top 5 Items IT Department Must Do</title><content type='html'>Even though it is a basic economic fact that recessions happen once or twice in a decade, when the economy is in a good shape, like it was a couple of years ago, people, including IT managers, tend to forget that the summer will be over and hard times will come soon. On the other hand, recessions might be bad but the current one is certainly worse than many of the ones before. Actually, this is the worst recession since the Great Depression in the 1930s and even the most optimistically-minded managers have really serious reasons to fear and be cautious.&lt;br /&gt;&lt;p&gt;We can't say that the recession took us by surprise but certainly we didn't expect it to be that fierce. However, recession or no recession, life must go on and if a company wants to make it, there are many things which can't be skipped. So, no matter that IT budgets are tight, there are items a company can't save on. &lt;strong&gt;Here are the top 5 items our IT department will not sacrifice:&lt;/strong&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/capsa/?prid=00060003"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 234px;" src="http://3.bp.blogspot.com/_LCrZaQE-Vo8/SeveQAjdrzI/AAAAAAAAFAo/jOY_xGWEat8/s320/shangwu2_372.jpg" alt="" id="BLOGGER_PHOTO_ID_5326595350903762738" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1, &lt;strong&gt;Network security and security in general&lt;/strong&gt;. Being in the network security business themselves, we know that network security and security in general is paramount and no matter how hard the economic situation might be, this is not an item to save on because the price is too high. Certainly, we are not buying the most expensive solutions, even though they are incredibly great but we also do not make compromises with the quality either.&lt;br /&gt;&lt;br /&gt;2, &lt;strong&gt;Going green. Going green is also an item we can't skip.&lt;/strong&gt; Green technology saves money and now this benefit is more important than ever. So, if we buy new IT stuff, we definitely go for the green items.&lt;br /&gt;&lt;br /&gt;3, &lt;strong&gt;Compliance.&lt;/strong&gt; Regulations compliance is another item we can't afford to skip, unless we really want to go out of business (and we don't). So, when there are steps in this direction to be taken, we do them – no way!&lt;br /&gt;&lt;br /&gt;4, &lt;strong&gt;Training.&lt;/strong&gt; Training is also important and even though our training budget has shrunk, we still try to keep our staff qualified.&lt;br /&gt;&lt;br /&gt;5, &lt;strong&gt;Outsourcing.&lt;/strong&gt; Outsourcing has been a successful strategy for our company at all times and now, when money issues start to surface, we are happy that outsourcing helps us cut cost with no sacrifice of quality.&lt;/p&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Kevin Chou is Author of this article from &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;www.Colasoft.com&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;About Colasoft Co., Ltd.&lt;br /&gt;Ever since 2001, Colasoft has been dedicated in providing all-in-one and easy-to-use Packet Sniffer software for network administrators and IT managers to monitor network activities, analyze network performance, enhance network security, and troubleshoot network problems. Up to now, more than 5000 customers in over 70 countries trust the flagship product – &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;Colasoft &lt;/a&gt;&lt;/span&gt;&lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;a&gt;Packet Sniffe&lt;/a&gt;r&lt;/span&gt;&lt;span style="font-size:85%;"&gt; as their network monitoring and troubleshooting solution. Colasoft also offers four free network utilities: Colasoft Packet Builder, Colasoft Packet Player, Colasoft MAC Scanner, and Colasoft Ping Tool. Learn more about Colasoft and its solutions, please visit &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;http://www.colasoft.com/&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-2099360267677333457?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/2099360267677333457/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/top-5-items-it-department-must-do.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/2099360267677333457'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/2099360267677333457'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/top-5-items-it-department-must-do.html' title='Top 5 Items IT Department Must Do'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LCrZaQE-Vo8/SeveQAjdrzI/AAAAAAAAFAo/jOY_xGWEat8/s72-c/shangwu2_372.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-1332343478336795609</id><published>2009-04-16T23:34:00.000-07:00</published><updated>2009-04-22T02:38:10.020-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer article'/><title type='text'>Analyze Protocols With Packet Sniffer</title><content type='html'>&lt;b&gt;&lt;strong&gt;What is Network Protocol?&lt;/strong&gt;&lt;/b&gt;&lt;br /&gt;A Protocol can be defined as rules governing  the syntax, semantics and synchronization of communication.&lt;br /&gt;In computing, A Protocol is a convention or standard that controls or enables the connection, communication and data transfer between two computing endpoints.&lt;br /&gt;Protocols may be implemented by Hardware, Software or a Combination of two. At the lowest level, a protocol defines the  behaviour of a hardware connection.&lt;p&gt;&lt;/p&gt;&lt;b&gt;Why  Protocol Analyzing Important?&lt;/b&gt;&lt;br /&gt;Since all network communications are based on  protocols and different protocols indicates varieties of network behaviours, by analyzing protocols using a Packet Sniffer, we get to know what network applications are used on the network and what network behaviour is taken  against your network. You may check out our protocols database to get an explanation of each protocol.&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;b&gt;&lt;strong&gt; Analyze Protocols With Packet Sniffer&lt;/strong&gt;&lt;/b&gt;&lt;br /&gt;A &lt;strong&gt;&lt;a href="http://www.colasoft.com/capsa/?prid=03060003"&gt;Packet Sniffer&lt;/a&gt;&lt;/strong&gt; is an important part of the &lt;strong&gt;Network Manager's toolkit&lt;/strong&gt;. Traditionally sniffers are  useful for troubleshooting networks and SNMP tools are better for trending and  service management. The combination of an SNMP based Performance Manager and a  well-featured &lt;strong&gt;Packet Sniffer&lt;/strong&gt; will allow you to perform many of the  fundamental tasks required for successful network management.&lt;br /&gt;&lt;br /&gt;Packet Sniffers, often called "packet sniffers" after Network Associates market leading Sniffer product, capture packets and decode them into their component parts. It's  fairly obvious how sniffers can be used to troubleshooting network problems.  Once a problem is detected packets are captured and analyzed and the details of  the communication can be worked out. But sniffers can do more than this and, in fact, turn out to be surprisingly useful in many aspects of network  management.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Unexpected  Traffic &lt;/strong&gt;&lt;br /&gt;The  obvious thing to do is monitor the network for unexpected traffic. Most network  managers know the types of application that they expect to see and can point  out anything unusual. If anything unexpected is spotted then a capture of some  of the traffic is usually sufficient to pinpoint the machines involved.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Unnecessary  Traffic &lt;/strong&gt;&lt;br /&gt;Many  machines to be set by default to run protocols that may not be required.&lt;br /&gt;For Example: Many printers broadcast using Novell's  IPX protocol. It is fine if you are using NetWare, but not always necessary.  It's good housekeeping to remove any protocols that you do not need. You may be concerned about how your users are using the available bandwidth. A good  sniffer will allow you to filter specific types of traffic, so that you can  keep an eye on any traffic that may cause you a problem.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Unauthorized Program Use &lt;/strong&gt;&lt;br /&gt;It is useful to check the specific port numbers for services on your Servers. Most common services operate on defined port numbers, a packet capture on a Server  will soon reveal what services are running. You can disable any services that  you do not need. This has two benefits, one, it avoids unnecessary traffic on  the network, and second it means that no unauthorized user can take advantage  of that service. If anyone is using a service a packet capture will show you  the address. Most sniffers allow filtering on specified port numbers so it is  possible to monitor continuously for specified port numbers.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Email Problems &lt;/strong&gt;&lt;br /&gt;Email systems typically use standard port numbers,  25 for SMTP, 143 for IMAP, 110 for POP3. Setting filters for these ports will  usually help to discover the cause of problems with email.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Virus Detection and Control &lt;/strong&gt;&lt;br /&gt;Antivirus software manufacturers offer updates services. Armed with the information on new threats it is often possible to build suitable filters to detect viruses. For example many sniffers allow you  to specify a text pattern, so a virus contained in a message containing a known  text string could be detected. Analysis of the capture will show the source and  destination of the packets.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Firewalls &lt;/strong&gt;&lt;br /&gt;Firewalls need to be checked for outgoing and  incoming traffic. You will have to define a set of filters for traffic in both  directions. Should the firewall begin to let unauthorized traffic through you need to be able to detect it.&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;strong&gt;For  Example: &lt;/strong&gt;&lt;/b&gt;&lt;br /&gt;&lt;strong&gt;TCP&lt;/strong&gt; is a Reliable connection oriented Protocol. Common Applications of TCP are Email and File Transfer. TCP is optimized for accurate delivery rather than timely delivery, and therefore, TCP sometimes incurs relatively long delays (in the order of seconds) while  waiting for out-of-order messages or retransmissions of lost messages. So TCP analysis is required with Colasoft Packet Sniffer for finding delays.&lt;br /&gt;&lt;strong&gt;UDP&lt;/strong&gt; is a Reliable  Connectionless Protocol. Common Applications of UDP are DNS, VOIP, IPTV and FTP.Sometimes Packet loss will happen during transmission and no help for this. Using Colasoft Packet Sniffer we can find  the loss&lt;br /&gt;&lt;strong&gt;HTTP&lt;/strong&gt; is a request/response  standard of a client and a server. A client is the end-user; the server is the  web site. The client making a HTTP request—using a web browser, spider or other  end-user tool—is referred to as the &lt;em&gt;user agent. &lt;/em&gt;The responding  server—which stores or creates &lt;em&gt;resources&lt;/em&gt; such as HTML files and  images—is called the &lt;em&gt;origin server&lt;/em&gt;. Certain design features of HTTP  interact badly with TCP, causing problems with performance and with server  scalability. Latency problems are caused by opening a single connection per  request, through connection setup and slow-start costs. Scalability problems  are caused by TCP requiring a server to maintain state for all recently closed  connections. Colasoft Packet Sniffer is used to  detection  such   problems.&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-1332343478336795609?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/1332343478336795609/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/analyze-protocols-with-packet-sniffer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/1332343478336795609'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/1332343478336795609'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/analyze-protocols-with-packet-sniffer.html' title='Analyze Protocols With Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-4579073353497170422</id><published>2009-04-16T20:13:00.000-07:00</published><updated>2009-04-22T02:38:39.106-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer howto'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>How to Protect Your Network with Packet Sniffer</title><content type='html'>&lt;b&gt;A packet sniffer (also called a &lt;a href="http://www.colasoft.com/?prid=00060003"&gt;network analyzer&lt;/a&gt;) can help you make your network more secure by identifying what's going on in it&lt;/b&gt; &lt;p&gt;Networks are large entities, even if they don't consist of thousands of machines. Large networks are especially vulnerable because they are a fruitful ground for attacks and hacking of all kinds. Even if a system administrator is a genius, he or she can't fight network security threats with bare hands.  &lt;/p&gt; &lt;h2&gt;Why Do You Need to Protect Your Network?&lt;/h2&gt; &lt;p&gt;One of the major principles in network security is that a network is as secure as its weakest part is. In other words, it makes no sense to invest tons of money and spend many hours to secure some of the parts of a network, when there are small vulnerabilities that can be easily abused.  &lt;/p&gt; &lt;p&gt;With networks small vulnerabilities are very common and even though one can never be sure that his or her network is secure, when no efforts in that direction are made, it is as sure as hell that this network is at risk. That is why it is absolutely clear that nobody can afford to leave a network unprotected. Fortunately, there are many tools, which help to protect a network and packet sniffers are one of them.  &lt;/p&gt; &lt;h2&gt;How a Packet Sniffer Can Protect Your Network?&lt;/h2&gt; &lt;p&gt;Packet sniffers (or network analyzers, as they are also called) can be one of the best tools you can use to protect your network. There are many types of network threats and there is no universal tool that can help you protect your network against all of them, so if you expect that a packet sniffer can safeguard your network against all kinds of threats, this is not so but it is a fact that a packet sniffer can help you against many threats, both internal and external.  &lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/capsa/?prid=03060003"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 326px;" src="http://2.bp.blogspot.com/_LCrZaQE-Vo8/Sefucq7q_LI/AAAAAAAAFAY/P1nloZu6jzo/s400/colasoft-network-sniffer-ss2.gif" alt="colasoft packet sniffer" id="BLOGGER_PHOTO_ID_5325487260717218994" border="0" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;A packet sniffer captures all the packets which go to and from your network and shows you their contents. While a packet sniffer is helpless against encrypted traffic, with unencrypted traffic a packet sniffer is an indispensable tool. When you have the chance to know what's going on in your network, you can easily spot the activities, which shouldn't be taking place.&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/products/?prid=03060003"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 326px;" src="http://3.bp.blogspot.com/_LCrZaQE-Vo8/Seft2ybaXiI/AAAAAAAAFAQ/t-vAup0Nko4/s400/colasoft-network-sniffer-ss1.gif" alt="colasoft packet sniffer" id="BLOGGER_PHOTO_ID_5325486609894366754" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;For instance, if somebody is downloading files with BitTorrent, or is generating any other kind of substantial traffic, a packet sniffer, such as &lt;a href="http://www.colasoft.com/capsa/?prid=00060003"&gt;Colasoft Packet Sniffer&lt;/a&gt;, will display this immediately and you will know that you should take the adequate measures to stop it. Actually, a packet sniffer allows to monitor all incoming and outgoing traffic and keep logs of this, so even if you don't react immediately when suspicious traffic occurs, all the traffic is logged and you can view it later.&lt;/p&gt; &lt;p&gt;Depending on the features of the packet sniffer you have selected, you will have different options to protect your network. Some of the packet sniffers with a rich feature set, for instance Colasoft Packet sniffer, offers a lot in terms of traffic monitoring. Generally, even the packet sniffers with less features allow to monitor suspicious activity at least from a given host or protocol.  &lt;/p&gt; &lt;p&gt;One of the cases when packet sniffers don't offer much help is with encrypted traffic. This is a technical limitation and even though packet sniffers can intercept encrypted packets, they can't break the encryption and show the actual content of the packet. However, when you are monitoring a network and you notice that there is unauthorized encrypted traffic (for instance from a given host), this should ring a bell that something not nice is probably going on and you should take the adequate measures to investigate what exactly is happening.  &lt;/p&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-4579073353497170422?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/4579073353497170422/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/how-to-protect-your-network-with-packet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/4579073353497170422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/4579073353497170422'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/how-to-protect-your-network-with-packet.html' title='How to Protect Your Network with Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LCrZaQE-Vo8/Sefucq7q_LI/AAAAAAAAFAY/P1nloZu6jzo/s72-c/colasoft-network-sniffer-ss2.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-8474002908972297436</id><published>2009-04-14T23:23:00.000-07:00</published><updated>2009-04-22T02:38:54.149-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer howto'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>How to Sniff All Images of a Webpage</title><content type='html'>In case we want to sniff all images of a webpage, here is a detailed process how we can do it with &lt;a href="http://www.colasoft.com/capsa/?prid=00060000"&gt;Colasoft Packet Sniffer&lt;/a&gt;’s "Logs" feature. I will take the CNN.com home page as an example.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Step 1. Open Log Settings&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Log settings allows us to set up some conditions or exceptions whether or not record some logs in the Logs tab. If we want to display just images in the Logs tab, we must enable the HTTP Log conditions.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss1.gif"&gt;&lt;img class="size-full wp-image-52" title="How to Sniff Images Screenshot 1" src="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss1.gif" alt="How to Sniff Images Screenshot 1" height="159" width="338" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Step 2. Enable Http Log Conditions&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;We must tick before Conditions to enable it&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss2.gif"&gt;&lt;img class="size-full wp-image-57" title="How to Sniff Images Screenshot 2" src="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss2.gif" alt="How to Sniff Images Screenshot 2" height="131" width="276" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Step 3. Input "Image" into Content Type&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;On the right hand, lets’ input the content type in order to filter contents&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss3.gif"&gt;&lt;img class="size-full wp-image-58" title="How to Sniff Images Screenshot 3" src="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss3.gif" alt="How to Sniffer Images Screenshot 3" height="188" width="291" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here is an explanation of Content Type&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss4.gif"&gt;&lt;img class="size-full wp-image-59" title="How to Sniff Images Screenshot 4" src="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss4.gif" alt="How to Sniff Images Screeshot 4" height="192" width="291" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Step 4. "OK" to Activate the Setting&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Now we’ve done with the Log Settings, let’s see whether we can sniff all images of CNN.com index page. First of all, let’s start capturing with Colasoft Packet Sniffer, then let’s input the URL into the address bar and start browsing.&lt;br /&gt;&lt;br /&gt;Results start showing in the Logs Tab – Http Request Option, we can see all results are in image formats. We have successfully sniffed all the images on this webpage.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss5.gif"&gt;&lt;img class="size-full wp-image-60" title="How to Sniff Images Screenshot 5" src="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss5.gif" alt="How to Sniff Images Screeshot 5" height="306" width="366" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;To view the image, we can click on the record, and it will be shown in a browser.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss6.gif"&gt;&lt;img src="http://blog.colasoft.com/wp-content/uploads/2009/04/sniff-images-ss6.gif" alt="How to Sniff Images Screenshot 6" title="How to Sniff Images Screenshot 6" class="size-full wp-image-62" height="144" width="292" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-8474002908972297436?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/8474002908972297436/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/how-to-sniff-all-images-of-webpage.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8474002908972297436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8474002908972297436'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/how-to-sniff-all-images-of-webpage.html' title='How to Sniff All Images of a Webpage'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-2386110668385135323</id><published>2009-04-13T00:42:00.000-07:00</published><updated>2009-04-15T00:52:32.552-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer article'/><title type='text'>Colasoft Packet Sniffer Capsa 6.9 Review</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_b4meHPrIBnY/SeL3Bk9NbBI/AAAAAAAAAHY/LnLsPZ4jiNs/s1600-h/1.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 210px;" src="http://4.bp.blogspot.com/_b4meHPrIBnY/SeL3Bk9NbBI/AAAAAAAAAHY/LnLsPZ4jiNs/s320/1.gif" alt="Colasoft Packet Sniffer Screenshot" id="BLOGGER_PHOTO_ID_5324089315977686034" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Overview&lt;/span&gt;&lt;br /&gt;Not so hard for a freshman.&lt;br /&gt;Auto diagnosis.&lt;br /&gt;Real time capture.&lt;br /&gt;If it's cheaper, I will definitely buy it!&lt;br /&gt;After using &lt;a href="http://www.colasoft.com/capsa/?prid=00060002"&gt;Colasoft Packet Sniffer&lt;/a&gt;, I found 3 features of this product:&lt;br /&gt;&lt;br /&gt;1.supports the real-time capturing and monitoring&lt;br /&gt;2.excellent capability of protocol analyzing (approximately 300 types) and packet decoding&lt;br /&gt;3.Well, the most exciting part is the automatic expert diagnosing! That really saves so much money and time for me, and I do not worry about the solution of failure again!&lt;br /&gt;&lt;br /&gt;Cost and performance are in desired level .&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What It Is and What It Can Do&lt;/span&gt;&lt;br /&gt;Colasoft Packet Sniffer is an expert packet sniffer and protocol analyzer designed for packet decoding and network diagnosis; it monitors the network traffic transmitted over a local host and a local network, with the ability of real time packet capture and accurate data analysis. Colasoft Packet Sniffer makes your network operations completely transparent before you, letting you isolate and troubleshoot network problems quickly and efficiently. The flexible and intuitive user interface lets either IT professionals or novice users skilfully handle it in a few moments.&lt;br /&gt;&lt;br /&gt;Easily understand how to use this packet sniffer with samples provided with the Tool. Sample packets helps me a lot for my first time deployment by avoiding  contacting the Technical Support  during  my initial days of using this Tool.&lt;br /&gt;&lt;br /&gt;For a Small Business Enterprise, This tool's network diagnosis helps me to detect slow network and upgraded   speed for better utilization.&lt;br /&gt;&lt;br /&gt;I prefer this for a Medium Business Enterprise as troubleshooting network issues is simply superb.&lt;br /&gt;&lt;br /&gt;For Medium and a Large Business Enterprises, Security is an issue.This packet sniffer enhances Network Security by monitoring the network with Logs. As every packet is recorded and analyzed, loopholes can easily detect.&lt;br /&gt;&lt;br /&gt;For every organization, security is a major concern. By using this tool Monitoring of Email Contents and Monitoring IMs, Chats is easy. Every information in Messegers, chats, HTTP Requests is logged .&lt;br /&gt;&lt;br /&gt;Can easily find where the problem from the Packet Analysis without letting the user to report about his huge traffic.&lt;br /&gt;&lt;br /&gt;For Internet Service Provider, this is very very useful tool. ISPs have problems of Server down issues due to huge traffics. By diagnosing with this tool, Server down issues can be reduced.&lt;br /&gt;Prevent hibernation while capturing and view both IP Addresses and Hostnames. This is a good feature in upgraded version.&lt;br /&gt;&lt;br /&gt;Colasoft Packet Sniffer Supports Windows Vista-64 bit Edition. Able to identify and Analyze 300+ Network Protocols.&lt;br /&gt;&lt;br /&gt;By going through the site &lt;a href="http://www.colasoft.com/?prid=00060002"&gt;www.colasoft.com&lt;/a&gt;, I came to know that Colasoft Packet Sniffer Professional Edition available  and  used it for Analyses. It really good to use and operate. Everything is logged and my network usage is monitored.&lt;br /&gt;&lt;br /&gt;Videos in the website help me to understand the ARP Attacks, Monitoring Network traffic. So I can protect my network now by identifying the deceived hosts and by identifying who is consuming maximum bandwidth in a Local Segment.&lt;br /&gt;&lt;br /&gt;I can monitor the traffic either by protocol, IP or MAC Address. So much flexibility in using this packet sniffer.&lt;br /&gt;&lt;br /&gt;Internet Service Providers can use this tool for quick issue troubleshooting. Easy to identify problems and minimizes the time to service the customer.&lt;br /&gt;&lt;br /&gt;The reports are displayed with Graphs and Tables .Viewing the connection in a matrix is wonderful and it is something special in Colasoft Packet Sniffer. This pictorial representation is really good to sort out the issue by easily detecting.&lt;br /&gt;&lt;br /&gt;Colasoft Packet Sniffer has the tools that would not find in other protocol analyzers, including ping and scan IPs and MACS across the LAN.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Summary&lt;/span&gt;&lt;br /&gt;Colasoft Packet Sniffer is an easy-to-use and all-in-one tool for IT Network Administrator, IT Consultant and for a Security Manager in IT Company.&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-2386110668385135323?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/2386110668385135323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/colasoft-packe-sniffer-capsa-69-review.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/2386110668385135323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/2386110668385135323'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/colasoft-packe-sniffer-capsa-69-review.html' title='Colasoft Packet Sniffer Capsa 6.9 Review'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_b4meHPrIBnY/SeL3Bk9NbBI/AAAAAAAAAHY/LnLsPZ4jiNs/s72-c/1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-3243135712720147470</id><published>2009-04-08T02:16:00.000-07:00</published><updated>2009-04-08T19:33:24.520-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer article'/><title type='text'>Packet Sniffer, Basic Tool for Network Administrators</title><content type='html'>&lt;a href="http://www.colasoft.com/products/?prid=0306001"&gt;&lt;img class="alignright size-medium wp-image-15" src="http://yournetworksniffer.wordpress.com/files/2009/04/distribution1.jpg?w=300" alt="packet sniffer screenshot" height="224" width="300" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Packet sniffers are a valuable tool for both network administrators and hackers. There are many &lt;a title="download colasoft packet sniffer" href="http://www.colasoft.com/download/?prid=03060001" target="_blank"&gt;packet sniffers&lt;/a&gt; on the market and one of the most sophisticated is the packet sniffer from &lt;a title="Colasoft Official Website" href="http://www.colasoft.com/?prid=03060001" target="_blank"&gt;Colasoft&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Packet sniffers are one of the best tools a &lt;/strong&gt;&lt;strong&gt;network administrator has at his or her disposal to analyze network traffic and to troubleshoot problems. &lt;/strong&gt;On the other hand, when a Packet sniffer is in the wrong hands – i.e. hackers use it – this can cause quite a lot of damage to a company or an individual, especially if the victim hasn't taken the required protective measures. You see, as with many things in life, packet sniffers can be a great tool to maintain a network, yet they can be very destructive, if misused.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Packet sniffers are very common, choose a best packet sniffer for you.&lt;/strong&gt; There are many packet sniffers on the market and they range from free, to cheap, to expensive, from very simple, to advanced, to packed with features. Each type of packet sniffers has its purposes and if you need a simple tool for quick results on a small network, you don't have to buy the most expensive packet sniffers, no matter that they have tons of features. But in reality, if you need a packet sniffer for professional use, low-end sniffers are not the answer and you need something more sophisticated, for example Colasoft Network Analyzer. Colasoft Network Analyzer is built around packet sniffing but includes many other useful features as well.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;As any other packet sniffer, the packet sniffer from Colasoft, intercepts and logs traffic, transmitted within a network (or a network segment).&lt;/strong&gt; A packet sniffer can be really invisible because it monitors the network (almost) unobtrusively. Since a packet sniffer just sniffs the packets without modifying them, it doesn't cause disturbances to alert the administrator that something is going on. Unless the administrator doesn't run an anti-sniffer, the traffic can be eavesdropped and nobody will know about it.&lt;br /&gt;&lt;br /&gt;Of course, a good network administrator knows how to detect a packet sniffer, so if you plan to get Colasoft packet sniffer and use it in a malicious way, don't expect that this will go unnoticed. The packet sniffer in the Colasoft Network Analyzer is not stealth but since anyway Colasoft Network Analyzer is intended for network troubleshooting, not network hacking, there is no reason to worry that the packet sniffer is not hidden. When a network administrator uses a packet sniffer in order to legitimately monitor network traffic, he or she doesn't need cover.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;One of the most important features of a packet sniffer is the &lt;/strong&gt;&lt;strong&gt;protocols it can sniff.&lt;/strong&gt; In this aspect &lt;a title="Colasoft packet sniffer software products" href="http://www.colasoft.com/products/?prid=03060001" target="_blank"&gt;Colasoft Network Analyzer&lt;/a&gt; is an unbeaten packet sniffer because it can monitor over 300 protocols. Colasoft knows that when the packets of major protocols are not captured, this gives a wrong impression about the traffic in the network and that is why Colasoft Network Analyzer supports so many protocols. And no, the protocols Colasoft Network Analyzer can sniff are not exotic ones – they are protocols used frequently in networks.&lt;br /&gt;&lt;br /&gt;Additionally, new and new protocols are added to the packet sniffer from Colasoft, so even if your network uses some really rare protocols, which are currently not supported by Colasoft Network Analyzer, they could be added in the future. Well, if you expect that the packet sniffer from Colasoft will sniff encrypted traffic, this will not happen because no packet sniffer can do it!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-3243135712720147470?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/3243135712720147470/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2009/04/packet-sniffer-basic-tool-for-network.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3243135712720147470'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3243135712720147470'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2009/04/packet-sniffer-basic-tool-for-network.html' title='Packet Sniffer, Basic Tool for Network Administrators'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-8460847912020629145</id><published>2008-12-02T00:38:00.000-08:00</published><updated>2009-04-08T19:25:23.396-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer howto'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>Network Troubleshooting Made Easy, A Colasoft Software Solution</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;span style="font-weight: bold;"&gt;The Challenge&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;As the business is becoming more and more networked, it’s always necessary for network administrators to troubleshoot network issues in shortest time possible if the network is not functioning properly. Network downtime or network malfunction may cause headaching inconvenience or even millions of business losses if not settled up in time. Without a handy tool, network troubleshooting can be time-consuming and frustrating.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Old Ways – Time-consuming and Frustrating&lt;/span&gt;&lt;br /&gt;There are a lot of articles providing guidance on how to troubleshoot network issues in general ways. For simple networking issues, these tutorials work fine. However, for a company-level network, issues are often complicated and mixed, and these issues require deeper analysis and stronger diagnosis abilities. Obviously, old ways are no longer suitable for today’s in-time network troubleshooting demands.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Troubleshooting Network Issues in Seconds&lt;/span&gt;&lt;br /&gt;To troubleshoot your network in time, even in seconds is now possible with Capsa’s diagnosis feature. Network issues are automatically detected and clearly identified, with possible causes and solutions provided.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Automatic Diagnosis&lt;/span&gt;&lt;br /&gt;Based on Colasoft’s packet analysis engine, Capsa is able to automatically detect network issues in different OSI layers, such as application layer, transport layer, and network layer. All these issues are marked with different severity levels, indicating which are critical issues that need to be addressed immediately, which are just informative messages.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;img src="http://lh5.ggpht.com/_b4meHPrIBnY/STT156-1BMI/AAAAAAAAAC0/RCaJxdHNig4/s400/at_diag.jpg" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;(Figure 1 Diagnosis Events List)&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Quick Locate Suspicious Host&lt;/span&gt;&lt;br /&gt;Once a critical network issue is detected and requires immediate handling, we can select the item from the list, then detailed information will be provided under, including source, destination, port and so on. We can easily locate the suspicious host in this field, for example, the attacking host or the host which is spamming our network. Moreover, after locating the suspicious host, we can conduct deeper analysis, such as protocol analyzing or packet decoding.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;img src="http://lh3.ggpht.com/_b4meHPrIBnY/STT1_7Vv3ZI/AAAAAAAAADc/bhI9hNiErXU/diag_detail.jpg" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;(Figure 2 Diagnosis Details)&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;Possible Causes &amp;amp; Solutions&lt;/span&gt;&lt;br /&gt;When selecting a network issue from the list, possible causes and solutions are also provided for users to understand the issue and solve it as soon as possible.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;img src="http://lh5.ggpht.com/_b4meHPrIBnY/STT16FYwrOI/AAAAAAAAAC8/SnMV60O-BBw/cau_sol.jpg" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;(Figure 3 Possible Causes &amp;amp; Solutions)&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;Customizable&lt;/span&gt;&lt;br /&gt;Depending on network sizes and network’s characteristics, we can customize the threshold that triggers one diagnosis event and the severity of the network issue.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;img src="http://lh4.ggpht.com/_b4meHPrIBnY/STT16fgejrI/AAAAAAAAADE/rOUaMwbKA1Q/dia_cus.jpgg" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;(Figure 4 Customize Threshold)&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Conclusion&lt;/span&gt;&lt;br /&gt;It is always good to maintain the network running smoothly and properly without any problems. However, if a network issue arises, we must make sure it is quickly detected and solved before it affects the entire infrastructure and brings loss to our business. For the complexity of the network and variety of network applications, network troubleshooting is becoming more challenging and demanding. To have a powerful tool like Capsa in hand is must in everyday’s network management.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;About Capsa&lt;/span&gt;&lt;br /&gt;Capsa is packet sniffer software designed for network monitoring and troubleshooting purposes. It performs real-time packet capturing, 24/7 network monitoring, advanced protocol analyzing, in-depth packet decoding, and automatic expert diagnosing. By giving users insights into all of the network's operations, Capsa makes it easy to isolate and solve network problems, identify network bottleneck and bandwidth use, and detect network vulnerabilities, external attacks and insecure applications.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;About Colasoft&lt;/span&gt;&lt;br /&gt;Ever since 2001, Colasoft has been dedicated in providing all-in-one and easy-to-use network analysis software for customers to monitor, analyze, and troubleshoot their network. Up to now, more than 4000 customers in over 70 countries trust the flagship product – Capsa as their network monitoring and troubleshooting solution. The company also offers four free network utilities: &lt;a href="http://www.colasoft.com/packet_builder/"&gt;Colasoft Packet Builder&lt;/a&gt;, &lt;a href="http://www.colasoft.com/packet_player/"&gt;Colasoft Packet Player&lt;/a&gt;, &lt;a href="http://www.colasoft.com/mac_scanner/"&gt;Colasoft MAC Scanner&lt;/a&gt;, and &lt;a href="http://www.colasoft.com/ping_tool/"&gt;Colasoft Ping Tool&lt;/a&gt;. Learn more today at &lt;a href="http://www.colasoft.com/"&gt;http://www.colasoft.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-8460847912020629145?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/8460847912020629145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/12/network-troubleshooting-made-easy.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8460847912020629145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8460847912020629145'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/12/network-troubleshooting-made-easy.html' title='Network Troubleshooting Made Easy, A Colasoft Software Solution'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_b4meHPrIBnY/STT156-1BMI/AAAAAAAAAC0/RCaJxdHNig4/s72-c/at_diag.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-3161556496178626216</id><published>2008-11-24T17:13:00.000-08:00</published><updated>2009-04-08T19:34:24.061-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer ABC'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer article'/><title type='text'>Top 10 Uses of Packet Sniffer Software</title><content type='html'>&lt;a href="http://www.colasoft.com/capsa"&gt;Packet Sniffer software&lt;/a&gt; is a network monitoring tool that helps us to be in control of our network 24/7. All computer networks that are connected to the internet are highly vulnerable to security risks. If our networks are not constantly monitored, we can easily become a prey for the hackers. Packet sniffer software logs all traffic and all data that is sent in and out of the network that matches the specific packet criteria set by the network administrator.&lt;br /&gt;&lt;br /&gt;Packet sniffer software has a number of uses and all of them are of critical nature.&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Whenever there is a network related problem, we need some basic clues so that we can start addressing the problems. We will be able to get these clues from the packet sniffer software that is installed in the network. Therefore, packet sniffer software will not only help us monitor the network, but it will also help us &lt;a href="http://www.colasoft.com/etherlook/"&gt;analyze the network traffic&lt;/a&gt; so that we can identify any problem that crops up in the shortest time possible. &lt;/li&gt;&lt;li&gt;If there are any unauthorized intrusions, we will be able to detect the intrusions in good time. This will help us protect our network from the hackers.&lt;/li&gt;&lt;li&gt;We will be able to &lt;a href="http://www.colasoft.com/capsa/network_bandwidth_analyzer.php"&gt;monitor the usage&lt;/a&gt; levels of the network at any given time. This will help us optimize the usage if we need to. &lt;/li&gt;&lt;li&gt;Using packet sniffer software we can keep a tab on each user in the network and gather sensitive information including passwords. &lt;/li&gt;&lt;li&gt;Packet sniffers will also be useful to monitor ‘on the fly’ network traffic to determine what is going on in the network at any given time. &lt;/li&gt;&lt;li&gt;Packet sniffers are not only useful for network administrators, it is also useful for programmers and security professionals to study the network traffic and possible loopholes so that they can be sealed.&lt;/li&gt;&lt;li&gt;Parents can keep a tab on their children’s online PC usage. &lt;/li&gt;&lt;li&gt;For those who are in learning stages packet sniffer will help them &lt;a href="http://www.colasoft.com/capsa/protocol_analyzer.php"&gt;understand various protocols&lt;/a&gt; of the network such as HTTP, POP3, STMP, etc. &lt;/li&gt;&lt;li&gt;The reports generated can be used to build reliable statistics about the network use. &lt;/li&gt;&lt;li&gt;You will be able to find reasons for system slowdown. Using the packet sniffer software you will be able to troubleshoot the problem in the shortest time possible. &lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;There many other uses besides the ones mentioned above. In addition, there are many packet sniffer software products available in the market. When you want to install packet sniffer software in your network, you must spend enough time in identifying the best packet sniffer software. The product you select should be a versatile tool and a popular product that has been tested in a variety of situations. It should be capable of handling  small as well as large network without causing any problems in the network. One of the best packet sniffer software available in the market is &lt;a href="http://www.colasoft.com/capsa"&gt;Colasoft Capsa&lt;/a&gt;. For more information about this versatile tool, visit &lt;a href="http://www.colasoft.com/"&gt;Colasoft.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;About Colasoft&lt;/span&gt;&lt;br /&gt;Ever since 2001, Colasoft has been dedicated in providing all-in-one and easy-to-use network analysis software for customers to monitor, analyze, and troubleshoot their network. Up to now, more than 4000 customers in over 70 countries trust the flagship product – Capsa as their network monitoring and troubleshooting solution. The company also offers four free network utilities: &lt;a href="http://www.colasoft.com/packet_builder/"&gt;Colasoft Packet Builder&lt;/a&gt;, &lt;a href="http://www.colasoft.com/packet_player/"&gt;Colasoft Packet Player&lt;/a&gt;, &lt;a href="http://www.colasoft.com/mac_scanner/"&gt;Colasoft MAC Scanner&lt;/a&gt;, and &lt;a href="http://www.colasoft.com/ping_tool/"&gt;Colasoft Ping Tool&lt;/a&gt;. Learn more today at &lt;a href="http://www.colasoft.com/"&gt;http://www.colasoft.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-3161556496178626216?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/3161556496178626216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/11/top-10-uses-of-packet-sniffer-software.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3161556496178626216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3161556496178626216'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/11/top-10-uses-of-packet-sniffer-software.html' title='Top 10 Uses of Packet Sniffer Software'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-4112173487929210085</id><published>2008-10-28T01:37:00.000-07:00</published><updated>2009-04-08T19:25:51.804-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Packet sniffer news'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>Colasoft Packet Sniffer Capsa 6.9 Released</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_b4meHPrIBnY/SPMn89KVV_I/AAAAAAAAAAs/F12B7araZOY/s320/colasoftlogo.gif" alt="colasoft logo" id="BLOGGER_PHOTO_ID_5256589118235039730" border="0" /&gt;&lt;/a&gt;(&lt;a href="http://www.colasoft.com/"&gt;colasoft.com&lt;/a&gt;) – Oct 21, 2008 - Colasoft, a dedicator in network analysis field, recently released version 6.9 of its flagship product – Capsa, a packet sniffer software designed for network monitoring and troubleshooting purpose. Two new protocols, Cisco Inter-Switch Link (ISL) and Fibre Channel over Ethernet (FCoE) now can be recognized and decoded. This latest version also improved user’s experience based on user’s feedbacks.&lt;br /&gt;&lt;br /&gt;Capsa is packet sniffer software which can perform real-time packet capturing, 24/7 network monitoring, advanced protocol analyzing, in-depth packet decoding, and automatic expert diagnosing. By giving users insights into all of the network's operations, Capsa makes it easy to isolate and solve network problems, identify network bottleneck and bandwidth use, and detect network vulnerabilities, external attacks and insecure applications.&lt;br /&gt;&lt;br /&gt;"We'll always take into consideration good suggestions from our customers", Said Roy Luo, the CEO of Colasoft, "and include them in future releases to ensure highest satisfaction."&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What’s New in Capsa 6.9&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Support ISL Protocol Decoding:&lt;/span&gt; Cisco Inter-Switch Link (ISL) is a Cisco Systems proprietary protocol that maintains VLAN information as traffic flows between switches and routers, or switches and switches. It is a protocol to encapsulate traffic from different vlans, and tag them for latter specification. Now all trunk traffic between switch -- switch or router -- switch can be decoded and the context inside of the trunk link can be analyzed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Support FCoE Protocol Decoding:&lt;/span&gt; Fibre Channel over Ethernet (FCoE) is a proposed mapping of Fibre Channel frames over selected full duplex IEEE 802.3 networks. This allows Fibre Channel to leverage 10 Gigabit Ethernet networks while preserving the Fibre Channel protocol. The specification is supported by a large number of network and storage vendors, including Cisco, EMC, HP, IBM, Intel, and Sun Microsystems.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;View IP address and Hostname in One Tab: &lt;/span&gt;Capsa will automatically resolve hostname and display it in its interface. In previous versions users may view only the hostname or the IP address at a time, they will need to switch manually if they want to view another value. In 6.9 users can directly view both the IP address and the hostname at the same time, which provides correlation between the two values&lt;br /&gt;&lt;br /&gt;"It's the easiest product to use. The support is excellent and the features added in subsequent releases are always well thought-out and beneficial to our company." Eric Gomez, CSO, InfoSight, Inc.&lt;br /&gt;&lt;br /&gt;Whether for a network administrator who needs to identify, diagnose, and solve network problems quickly, an IT professional who wants to monitor user activities on the network, a security manager who needs to ensure that the corporation's communications assets are safe, or a consultant who has to quickly solve network problems for clients, Capsa has the functions that satisfy the diversified needs perfectly.&lt;br /&gt;&lt;br /&gt;Capsa 6.9 runs under Windows 2000/XP/2003/Vista. A trial version is available at the company's web site: &lt;a href="http://www.colasoft.com/"&gt;http://www.colasoft.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;About Colasoft&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ever since 2001, Colasoft has been dedicated in providing all-in-one and easy-to-use network analysis software for customers to monitor, analyze, and troubleshoot their network. Up to now, more than 4000 customers in over 70 countries trust the flagship product – Capsa as their network monitoring and troubleshooting solution. The company also offers four free network utilities: &lt;a href="http://www.colasoft.com/packet_builder/index.php"&gt;Colasoft Packet Builder&lt;/a&gt;, &lt;a href="http://www.colasoft.com/packet_player/index.php"&gt;Colasoft Packet Player&lt;/a&gt;, &lt;a href="http://www.colasoft.com/mac_scanner/mac_scanner.php"&gt;Colasoft MAC Scanner&lt;/a&gt;, and &lt;a href="http://www.colasoft.com/ping_tool/index.php"&gt;Colasoft Ping Tool&lt;/a&gt;. Learn more today at http://www.colasoft.com/&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-4112173487929210085?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/4112173487929210085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/10/colasoft-packet-sniffer-capsa-69.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/4112173487929210085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/4112173487929210085'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/10/colasoft-packet-sniffer-capsa-69.html' title='Colasoft Packet Sniffer Capsa 6.9 Released'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_b4meHPrIBnY/SPMn89KVV_I/AAAAAAAAAAs/F12B7araZOY/s72-c/colasoftlogo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-3931197452810151796</id><published>2008-10-25T19:26:00.000-07:00</published><updated>2008-10-25T19:43:26.137-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wireshark'/><title type='text'>Wireshark 1.0.4 Just Released, Download Now</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_b4meHPrIBnY/SQHyaKZwc9I/AAAAAAAAACQ/uNfVZ4z6F9w/s1600-h/wireshark.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 317px; height: 95px;" src="http://4.bp.blogspot.com/_b4meHPrIBnY/SQHyaKZwc9I/AAAAAAAAACQ/uNfVZ4z6F9w/s320/wireshark.png" alt="" id="BLOGGER_PHOTO_ID_5260752371028358098" border="0" /&gt;&lt;/a&gt;(Oct 20, 2008) Wireshark 1.0.4 has been released. Installers for Windows, Mac OS X Intel 10.5, and source code is now available.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;In this release&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Security-related bugs in the Bluetooth ACL, Bluetooth RFCOMM, PRP, Q.931, MATE, and USB dissectors, as well as the Tammos CommView file parser have been fixed. See the advisory for details.&lt;br /&gt;&lt;br /&gt;Many other bugs have been fixed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What's New&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bug Fixes&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following vulnerabilities have been fixed. See the security advisory for details and a workaround.&lt;br /&gt;&lt;br /&gt;1. Florent Drouin and David Maciejak found that the Bluetooth ACL dissector could crash or abort. (Bug 1513)&lt;br /&gt;&lt;br /&gt;Versions affected: 0.99.2 to 1.0.3&lt;br /&gt;&lt;br /&gt;2. The Q.931 dissector could crash or abort. (Bug 2870)&lt;br /&gt;&lt;br /&gt;Versions affected: 0.10.3 to 1.0.3&lt;br /&gt;&lt;br /&gt;3. Wireshark could abort while reading Tamos CommView capture files. (Bug 2926)&lt;br /&gt;&lt;br /&gt;Versions affected: 0.99.7 to 1.0.3&lt;br /&gt;&lt;br /&gt;4. David Maciejak found that the USB dissector could crash or abort. This led to the discovery of a similar problem in the Bluetooth RFCOMM dissector. (Bug 2922)&lt;br /&gt;&lt;br /&gt;Versions affected: 0.99.7 to 1.0.3&lt;br /&gt;&lt;br /&gt;5. Vivek Gupta and David Maciejak found that the PRP and MATE dissectors could make Wireshark crash. (Neither PRP nor MATE are enabled by default.) (Bug 2549)&lt;br /&gt;&lt;br /&gt;Versions affected: 0.99.2 to 1.0.3&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The following bugs have been fixed:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Let MP2T call its subdissectors, even without tree (Bug 2627)&lt;br /&gt;&lt;br /&gt;Wireless Toolbar not enabled (using AirPcap) if PCAP_REMOTE=1 (Bug 2685)&lt;br /&gt;&lt;br /&gt;Failure to dissect long SASL wrapped LDAP response (Bug 2687)&lt;br /&gt;&lt;br /&gt;Fix compiler warnings (Bug 2823)&lt;br /&gt;&lt;br /&gt;Homeplug dissection bugs (Bug 2859)&lt;br /&gt;&lt;br /&gt;Malformed Packet DCP ETSI error (Bug 2860)&lt;br /&gt;&lt;br /&gt;Wrong size of selected_registrar in WPS dissector (Bug 2865)&lt;br /&gt;&lt;br /&gt;Dissector assertion displaying cookies in DTLS frames (Bug 2876)&lt;br /&gt;&lt;br /&gt;Missing field type in documentation (Bug 2889)&lt;br /&gt;&lt;br /&gt;Wireshark -p switch seems to have no effect to PROMISCUOUS mode (Bug 2891)&lt;br /&gt;&lt;br /&gt;Misspelled PPI error vector magnitude filter (Bug 2903)&lt;br /&gt;&lt;br /&gt;Modbus Function 43 Encapsulated Interface Transport decoding (Bug 2917)&lt;br /&gt;&lt;br /&gt;Crash when printing or exporting some protocol data (Bug 2934)&lt;br /&gt;&lt;br /&gt;Crash when selecting "Export Selected Packet Bytes" (Bug 2964)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;New and Updated Features&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;There are no new or updated features in this release.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;New Protocol Support&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;There are no new protocols in this release.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Updated Protocol Support&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;AFP, Bluetooth ACL, Bluetooth RFCOMM, DCP ETSI, DTLS, Homeplug, IEEE 802.11, IP, Modbus TCP, MP2T, NSIP, NCP, PPI, Q.931, SASL, SNMP, USB, WPS&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What is Wireshark?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development, and education.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Download Wireshark 1.0.4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The latest version can be downloaded here: &lt;a href="http://www.wireshark.org/download.html"&gt;http://www.wireshark.org/download.html&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;addthis_url='&lt;data:post.url/&gt;'; addthis_title='&lt;data:post.title/&gt;'; addthis_pub='snifferclub';&lt;/script&gt;&lt;script src="http://s7.addthis.com/js/addthis_widget.php?v=12" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button for Post END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-3931197452810151796?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/3931197452810151796/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/10/wireshark-104-just-released-download.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3931197452810151796'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3931197452810151796'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/10/wireshark-104-just-released-download.html' title='Wireshark 1.0.4 Just Released, Download Now'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_b4meHPrIBnY/SQHyaKZwc9I/AAAAAAAAACQ/uNfVZ4z6F9w/s72-c/wireshark.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-6780365184904645658</id><published>2008-10-24T08:45:00.000-07:00</published><updated>2008-10-24T09:09:25.500-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wireshark'/><title type='text'>Wireshark Multiple Vulnerabilities</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_b4meHPrIBnY/SQHyaKZwc9I/AAAAAAAAACQ/uNfVZ4z6F9w/s1600-h/wireshark.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 317px; height: 95px;" src="http://4.bp.blogspot.com/_b4meHPrIBnY/SQHyaKZwc9I/AAAAAAAAACQ/uNfVZ4z6F9w/s320/wireshark.png" alt="" id="BLOGGER_PHOTO_ID_5260752371028358098" border="0" /&gt;&lt;/a&gt;Wireshark (&lt;a href="http://www.wireshark.org/"&gt;http://www.wireshark.org/&lt;/a&gt;) is the most popular network &lt;a href="http://www.colasoft.com/capsa"&gt;protocol analyzer&lt;/a&gt; (aka "sniffer").&lt;br /&gt;&lt;br /&gt;A memory corruption vulnerability exists in Wireshark, potentially allowing a remote attacker to compromise targeted systems by sending them specially crafted "live" network traffic or malicious network trace files (pcap files).&lt;br /&gt;&lt;br /&gt;Multiple denial of service vulnerabilities also exist in Wireshark, allowing a remote attacker to crash targeted systems upon sniffing network traffic or viewing network trace files (pcap files).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Impact:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Full compromise of the targeted system.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Risk:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;High&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Affected Software:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Wireshark version older than 1.0.4&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Additional Information:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The Bluetooth HCI memory corruption vulnerability lies in the BTHCI packet dissector and is caused by insufficient checking of packet parameters. This issue occurs either when Wireshark is configured to sniff Bluetooth traffic (with an USB dongle for example) and sent "live" malicious traffic, or upon opening a crafted Bluetooth HCI encapsulation format traffic file.&lt;br /&gt;&lt;br /&gt;The Parallel Redundancy Protocol post-dissector (not enabled by default) is vulnerable to a denial of service when handling specially crafted Ethernet frames; the issue is caused by a missing exception handling.&lt;br /&gt;&lt;br /&gt;The USB URB denial of service vulnerability lies in the USB packet dissector, where insufficient checking of packet parameters is performed; the vulnerability is present only when Wireshark is configured to sniff packets from USB ports or opens a crafted USB traffic pcap file.&lt;br /&gt;&lt;br /&gt;The two denial of service conditions above may be used by an attacker as a Cyber Counter-Measures tool, in order to render the network surveillance systems "blind" before engaging in further deleterious action.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Solutions:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Upgrade to latest version available from &lt;a href="http://www.wireshark.org/download.html"&gt;http://www.wireshark.org/download.html&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Do not open pcap traffic files received from unknown source.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;References:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Wireshark advisory is available at &lt;a href="http://www.wireshark.org/security/wnpa-sec-2008-06.html"&gt;http://www.wireshark.org/security/wnpa-sec-2008-06.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2924"&gt;Bluetooth HCI memory corruption&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2949"&gt;Parallel Redundancy Protocol denial of service&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2922"&gt;USB URB dissector denial of service&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Acknowledgment:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;David Maciejak of Fortinet's FortiGuard Global Security Research Team&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Disclaimer:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Although Fortinet has attempted to provide accurate information in these materials, Fortinet assumes no legal responsibility for the accuracy or completeness of the information. More specific information is available on request from Fortinet. Please note that Fortinet's product information does not constitute or contain any guarantee, warranty or legally binding representation, unless expressly identified as such in a duly signed writing.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;About Fortinet ( &lt;a href="http://www.fortinet.com/"&gt;www.fortinet.com &lt;/a&gt;):&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Fortinet is the pioneer and leading provider of ASIC-accelerated unified threat management, or UTM, security systems, which are used by enterprises and service providers to increase their security while reducing total operating costs. Fortinet solutions were built from the ground up to integrate multiple levels of security protection--including firewall, antivirus, intrusion prevention, VPN, spyware prevention and anti-spam -- designed to help customers protect against network and content level threats. Leveraging a custom ASIC and unified interface, Fortinet solutions offer advanced security functionality that scales from remote office to chassis-based solutions with integrated management and reporting. Fortinet solutions have won multiple awards around the world and are the only security products that are certified in six programs by ICSA Labs: (Firewall, Antivirus, IPSec, SSL, Network IPS, and Anti-Spyware). Fortinet is privately held and based in Sunnyvale, California.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-6780365184904645658?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/6780365184904645658/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/10/wireshark-multiple-vulnerabilities.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/6780365184904645658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/6780365184904645658'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/10/wireshark-multiple-vulnerabilities.html' title='Wireshark Multiple Vulnerabilities'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_b4meHPrIBnY/SQHyaKZwc9I/AAAAAAAAACQ/uNfVZ4z6F9w/s72-c/wireshark.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-8013198188319195799</id><published>2008-10-15T22:19:00.000-07:00</published><updated>2009-04-22T02:40:00.027-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer howto'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>How to Monitor Network Traffic with Packet Sniffer</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_b4meHPrIBnY/SPMn89KVV_I/AAAAAAAAAAs/F12B7araZOY/s320/colasoftlogo.gif" alt="colasoft logo" id="BLOGGER_PHOTO_ID_5256589118235039730" border="0" /&gt;&lt;/a&gt;There are quite a lot of software (both free and commercial) out there that perform network traffic monitoring tasks. But this article is to discuss how we can monitor network traffic with &lt;a href="http://snifferclub.blogspot.com/2008/10/packet-sniffer-brief-introduction.html"&gt;packet sniffer&lt;/a&gt; software. Among these packet sniffers, Colasoft Packet Sniffer is highly recommended as it is easy to use and thorough in data analysis. You can &lt;a href="http://colasoft.com/download/products/capsa.php"&gt;click here&lt;/a&gt; to download a trial version of Colasoft Packet Sniffer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Get a Real-ime network traffic Trend Chart&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If we want to get a trend chart of the network traffic, then we need to use the "Graphs" tab. "Graphs" view allows us view network statistics dynamically in different chart types, such as ling chart, bar chart, and pie chart. By selecting "Utilization" we get a real-time network traffic trend chart.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic5.gif" alt="monitor network traffic with colasoft packet sniffer graph1" /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Learn How Much network traffic Has Been Generated by What Network Protocol&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;"Protocols" view will list all protocols applied in network transmission. In "Protocols" view we can &lt;a href="http://www.coalsoft.com/etherlook/"&gt;monitor network traffic&lt;/a&gt; by each protocol. By analyzing network traffic by protocol, we can understand what applications are using the network bandwidth, for example "http" protocol stands for website browsing, "pop3" stands for email, etc.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic2.gif" alt="monitor network traffic with colasoft packet sniffer graph2" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Learn Which Host Has Generated or Is Generating How Much network traffic&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In "Endpoints" view, we can monitor network traffic information of each node, both local and remote. In this tab we can monitor the aggregated network traffic and the real-time network traffic generated by each host (listed as IP addressess and MAC addresses). With its easy sorting feature we can easily find out which host is generating or has generated the largest network traffic.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic1.gif" alt="monitor network traffic with colasoft packet sniffer graph3" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Monitor network traffic Generated by Each Network Conversation&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In "Conversations" tab we can monitor network traffic by each conversation and the figure out which conversation has generated the largest network traffic.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic3.gif" alt="monitor network traffic with colasoft packet sniffer graph4" /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Inbound network traffic, Outbound network traffic, Broadcast network traffic and So on&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In "Summary" we can get a quick view of the total network traffic, real-time network traffic, broadcast network traffic, multicast network traffic and so on. When we switch among the node from the explorer, corresponding network traffic information will be provided.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.colasoft.com/images/screenshots/monitor_network_traffic6.gif" alt="monitor network traffic with colasoft packet sniffer graph5" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.colasoft.com/capsa/"&gt;Colasoft Packet Sniffer - Capsa&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Capsa is packet sniffer software designed for network monitoring and troubleshooting purpose. It performs real-time packet capturing, 24/7 network monitoring, advanced protocol analyzing, in-depth packet decoding, and automatic expert diagnosing. By giving users insights into all of the network's operations, Capsa makes it easy to isolate and solve network problems, identify network bottleneck and bandwidth use, and detect network vulnerabilities, external attacks and insecure applications.&lt;br /&gt;&lt;br /&gt;Capsa runs under Windows 2000/XP/2003/Vista. A trial version is available at the company's web site: &lt;a href="http://www.colasoft.com/"&gt;http://www.colasoft.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-8013198188319195799?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/8013198188319195799/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/10/how-to-monitor-network-traffic-with.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8013198188319195799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/8013198188319195799'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/10/how-to-monitor-network-traffic-with.html' title='How to Monitor Network Traffic with Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_b4meHPrIBnY/SPMn89KVV_I/AAAAAAAAAAs/F12B7araZOY/s72-c/colasoftlogo.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-6748851528006591518</id><published>2008-10-13T02:43:00.000-07:00</published><updated>2009-04-08T19:28:11.207-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer howto'/><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><title type='text'>How to Deploy a Packet Sniffer</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.colasoft.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_b4meHPrIBnY/SPMn89KVV_I/AAAAAAAAAAs/F12B7araZOY/s320/colasoftlogo.gif" alt="colasoft logo" id="BLOGGER_PHOTO_ID_5256589118235039730" border="0" /&gt;&lt;/a&gt;Before we can analyze and monitor a network with a &lt;a href="http://www.colasoft.com/" title="colasoft packet sniffer"&gt;packet sniffer&lt;/a&gt;, we must make sure the packet sniffer is correctly deployed at the right place, so that we can capture all the traffic running in and out. The installation of a &lt;a href="http://snifferclub.blogspot.com/2008/10/packet-sniffer-brief-introduction.html" title="what is packet sniffer,packet sniffer introduction"&gt;packet sniffer&lt;/a&gt; is easy, it is always a good idea to install a packet sniffer on a laptop, so that the laptop can be shifted around to troubleshoot different network segments. This article will discuss how to deploy a packet sniffer based on the different network device that is used.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;How to Deploy a Packet Sniffer in a Switched Network&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Switch is a network device working on the Data Link Layer of OSI. Switch can learn the physical addresses and save these addresses in its ARP table. When a packet is sent to switch, switch will check the packet’s destination address from its ARP table and then send the packet to the corresponding port.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Condition 1: Manageable Switch&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Generally all three-layer switches and partial two-layer switches are manageable; the traffic going through other ports of the switch can be captured from the debugging port (mirror port/span port) on the core chip. To analyze the traffic going through all ports, we should deploy a packet sniffer at this debugging port (mirror port/span port). In a manageable switch network environment, we should deploy a packet sniffer like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_b4meHPrIBnY/SPMmo7OjqHI/AAAAAAAAAAc/xgBCsFclZ3A/s1600-h/packet-sniffer-deployment2.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_b4meHPrIBnY/SPMmo7OjqHI/AAAAAAAAAAc/xgBCsFclZ3A/s320/packet-sniffer-deployment2.gif" alt="packet" sniffer="" deployment2="" id="BLOGGER_PHOTO_ID_5256587674606872690" border="1" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Condition 2: Unmanageable Switch&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If our switch has no management function, we can connect a tap with the line to be monitored. Taps can be flexibly placed on any line in network. When requiring high network performance, we can add a tap to our network. In an unmanageable switch network environment, we should deploy a packet sniffer like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_b4meHPrIBnY/SPMnmWbGJyI/AAAAAAAAAAk/pD1n8NTQQbY/s1600-h/packet-sniffer-deployment3.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_b4meHPrIBnY/SPMnmWbGJyI/AAAAAAAAAAk/pD1n8NTQQbY/s320/packet-sniffer-deployment3.gif" alt="" id="BLOGGER_PHOTO_ID_5256588729879242530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;How to Deploy a Packet Sniffer in a Hubbed Network&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A hubbed network is also known as shared network which is connected with a hub. In a hubbed environment, packet sniffer can be installed on any host in LAN. The entire network data transmitted through the Hub will be captured, including the communication between any two hosts in LAN, because when a packet arrives at one port, it is copied to the other ports so that all segments of the LAN can see all packets. In a hubbed network,  we should deploy a packet sniffer as shown below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_b4meHPrIBnY/SPMlILRoaMI/AAAAAAAAAAU/9atsqRU3Q_g/s1600-h/packet-sniffer-deployment1.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_b4meHPrIBnY/SPMlILRoaMI/AAAAAAAAAAU/9atsqRU3Q_g/s320/packet-sniffer-deployment1.gif" alt="packet sniffer deployment1" id="BLOGGER_PHOTO_ID_5256586012467423426" border="1" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-6748851528006591518?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/6748851528006591518/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/10/how-to-deploy-packet-sniffer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/6748851528006591518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/6748851528006591518'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/10/how-to-deploy-packet-sniffer.html' title='How to Deploy a Packet Sniffer'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_b4meHPrIBnY/SPMn89KVV_I/AAAAAAAAAAs/F12B7araZOY/s72-c/colasoftlogo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-1667753143097688476</id><published>2008-10-10T01:06:00.000-07:00</published><updated>2008-10-13T02:39:09.322-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Packet sniffer news'/><category scheme='http://www.blogger.com/atom/ns#' term='InfiniStream'/><category scheme='http://www.blogger.com/atom/ns#' term='Network General'/><category scheme='http://www.blogger.com/atom/ns#' term='NetScount'/><category scheme='http://www.blogger.com/atom/ns#' term='nGenius'/><title type='text'>NetScout has released nGenius Performance Manager and nGenius InfiniStream version 4.5</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_b4meHPrIBnY/SPKy3Og4veI/AAAAAAAAAAM/jEcCLsEdYnQ/s1600-h/netscout-newlogo.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_b4meHPrIBnY/SPKy3Og4veI/AAAAAAAAAAM/jEcCLsEdYnQ/s320/netscout-newlogo.jpg" alt="Netscout logo" id="BLOGGER_PHOTO_ID_5256460376953372130" border="0" /&gt;&lt;/a&gt;NetScout Systems, a provider of network performance management software, has released nGenius Performance Manager and nGenius InfiniStream version 4.5 software, and the evolution of its nGenius InfiniStream continuous capture Deep Packet Inspection devices, the company's next step in executing on the integration of its acquisition of Network General.&lt;br /&gt;&lt;br /&gt;The result is a unified solution that raises the bar in service assurance and performance management by combining early-warning capabilities, real-time and historical application flow analysis, and deep-packet forensics. The result of this evolution will have a profound impact on IT operations by enabling network, datacenter and application managers to dramatically improve productivity through more effective collaboration to address the operational challenges of managing the modern IP network posed by virtualization, convergence, SOA and highly distributed network-centric operations.&lt;br /&gt;&lt;br /&gt;According to the company, the evolution of the nGenius Performance Management solution integrates the functionality of NetScout's real-time monitoring and rapid top-down troubleshooting and analysis with the former Network General's expert packet analysis and data-mining capabilities.&lt;br /&gt;&lt;br /&gt;As part of the product unification, elements from both product lines have come together under the nGenius Performance Management umbrella, with application intelligence and data mining capabilities retaining the well-established Sniffer branding. NetScout has also unified its family of continuous capture Deep Packet Inspection (DPI) devices, formerly known as nGenius AFMon and Sniffer InfiniStream, as nGenius InfiniStream. The new nGenius InfiniStream DPI devices retain important elements from both product lines delivering operational consistency with a flexible range of interface options and storage capacities to meet the most demanding high-performance requirements.&lt;br /&gt;&lt;br /&gt;NetScout's thoughtful approach to the integration of Sniffer portfolio into the nGenius portfolio enables customers to efficiently leverage their existing investments and benefit from the blended technical capabilities of two platforms. Companies that have deployed both platforms further benefit as this latest software release allows for the consolidation and unification of performance management tools with an easy-to-deploy migration path that delivers a best of both worlds approach.&lt;br /&gt;&lt;br /&gt;Michael Szabados, COO of NetScout, said: "The integration of nGenius and Sniffer technologies into a single, unified solution brings enormous power to our expanded customer base and new customers alike. Managing the Modern IP Network requires a transformative approach to how networks are managed. This latest release of NetScout's nGenius technology addresses this need by bringing top-to-bottom intelligent views that empowers IT managers to solve the hardest performance challenges while providing unmatched investment preservation and delivering greater business value to our customers."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-1667753143097688476?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/1667753143097688476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/10/netscout-has-released-ngenius.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/1667753143097688476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/1667753143097688476'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/10/netscout-has-released-ngenius.html' title='NetScout has released nGenius Performance Manager and nGenius InfiniStream version 4.5'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_b4meHPrIBnY/SPKy3Og4veI/AAAAAAAAAAM/jEcCLsEdYnQ/s72-c/netscout-newlogo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-7163317407546234611</id><published>2008-10-09T18:46:00.000-07:00</published><updated>2009-04-08T19:28:47.170-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='colasoft'/><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer article'/><title type='text'>Top Reasons Why Academic Users Need Packet Sniffer Software</title><content type='html'>Academic users need &lt;a href="http://www.colasoft.com/" title="colasoft packet sniffer software"&gt;packet sniffer software&lt;/a&gt; for various reasons in their daily works, such as network performance monitoring, network behaviors supervising ,conceptual items demonstrating and so on. Two packet sniffers are highly recommended for such users.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Why Academic Users Need Packet Sniffer Software&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;For an academic network administrator &lt;/span&gt;who needs to make sure the network is running smoothly and reliably, he will need packet sniffer software for:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Monitoring network performance around the clock,&lt;/li&gt;&lt;li&gt;Supervising various kinds of network behaviors,&lt;/li&gt;&lt;li&gt;Protecting network from suspicious intentions and attacks,&lt;/li&gt;&lt;li&gt;Discovering network loopholes and network bottlenecks,&lt;/li&gt;&lt;li&gt;Identifying and troubleshoot network problems in time,&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;For an academic teaching staff&lt;/span&gt; who needs to explain and demonstrate conceptual items to his students, he will need packet sniffer software for:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Demonstrating how a service (such as DNS, DHCP) works for your network,&lt;/li&gt;&lt;li&gt;Demonstrate the detail information within a packet of some sort of specific protocol,&lt;/li&gt;&lt;li&gt;Demonstrate the network behaviors of an application,&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;For an academic researcher and developer&lt;/span&gt;, he will need packet sniffer software for:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Network protocols research purpose&lt;/li&gt;&lt;li&gt;Debug network relied applications&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;For an academic student&lt;/span&gt;, he will need packet sniffer software for his studying and researching purposes.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Suggested Packet Sniffer Software&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.blogger.com/www.wireshark.org"&gt;Wireshark&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Wireshark is a free network packet sniffer developed by an international team of networking experts. Its key features include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Deep inspection of hundreds of protocols, with more being added all the time&lt;/li&gt;&lt;li&gt;Live capture and offline analysis&lt;/li&gt;&lt;li&gt;Standard three-pane packet browser&lt;/li&gt;&lt;li&gt;Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others&lt;/li&gt;&lt;li&gt;Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility&lt;/li&gt;&lt;li&gt;The most powerful display filters in the industry&lt;/li&gt;&lt;li&gt;Rich VoIP analysis&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;a href="http://www.colasoft.com/capsa"&gt;Colasoft Packet Sniffer&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you are looking for a cost-effective and easy-to-use packet sniffer, then you should take a look at Capsa, a packet sniffer produced by Colasoft Co., Ltd. Its key features include:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Monitor traffic and bandwidth details in graphs and numbers.&lt;/li&gt;&lt;li&gt;Automatically diagnoses network and suggests solutions.&lt;/li&gt;&lt;li&gt;Able to identify and analyze 300+ network protocols.&lt;/li&gt;&lt;li&gt;Provides packet summary and decoding information.&lt;/li&gt;&lt;li&gt;Monitors site visits, email contents, online chats, and more.&lt;/li&gt;&lt;li&gt;Lists all hosts in network with details (traffic, IP, MAC, etc.).&lt;/li&gt;&lt;li&gt;Visualizes the entire network in an ellipse, showing connections and traffic.&lt;/li&gt;&lt;li&gt;Monitor all conversations and reconstruct packet stream.&lt;/li&gt;&lt;li&gt;Free built-in tools to create and replay packets; scan and ping IPs.&lt;/li&gt;&lt;li&gt;Quick generates reports of most concerned items.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;Capsa runs under Windows 2000/XP/2003/Vista. You can &lt;a href="http://www.colasoft.com/download/products/capsa.php"&gt;click here&lt;/a&gt; to download a trial version of Capsa.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-7163317407546234611?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/7163317407546234611/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/10/top-reasons-why-academic-users-need.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/7163317407546234611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/7163317407546234611'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/10/top-reasons-why-academic-users-need.html' title='Top Reasons Why Academic Users Need Packet Sniffer Software'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8522588641740201139.post-3617420289030531689</id><published>2008-10-09T06:57:00.000-07:00</published><updated>2008-10-09T07:25:08.319-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='packet sniffer ABC'/><title type='text'>Packet Sniffer, A Brief Introduction</title><content type='html'>A&lt;a href="http://www.colasoft.com" title="Colasoft packet sniffer"&gt; packet sniffer&lt;/a&gt; is a piece of software that grabs all of the traffic flowing into and out of a computer attached to a network. They are available for several platforms in both commercial and open-source variations. Some of simplest packages are actually quite easy to implement in C or Perl, use a command line interface and dump captured data to the screen. More complex projects use a GUI, graph traffic statistics, track multiple sessions and offer several configuration options. Packet sniffer are also the engines for other programs. Intrusion Detection Systems (IDS) use packet sniffer to match packets against a rule-set designed to flag anything malicious or strange. &lt;a href="http://www.colasoft.com/capsa/network_bandwidth_analyzer.php" title="network utilization monitor, network utilizaiton analyer"&gt;Network utilization and monitoring&lt;/a&gt; programs often use packet sniffer to gather data necessary for metrics and analysis. Law enforcement agencies that need to monitor email during investigations, likely employ a packet sniffer designed to capture very specific traffic.&lt;br /&gt;&lt;br /&gt;A &lt;a href="http://www.colasoft.com/capsa" title="Colasoft Capsa packet sniffer"&gt;packet sniffer&lt;/a&gt; can be an invaluable tool for administrators, security professionals, programmers and even beginners. They are excellent utilities for troubleshooting any type of network problem, since they provide a window into local traffic. I personally have used packet sniffer on multiple occasions for security work and once discovered a compromised machine that periodically sent updates to a cracker. For network programming, a packet sniffer is a necessity for debugging in the development stages. Packet sniffer are an outstanding resource for the curious beginner, who hopes to understand both networks and security. Nothing can bring you closer to what really happens, when computers communicate, than these tools.&lt;br /&gt;&lt;br /&gt;It should be noted that the casual user should be very cautious when, where and how they use these programs. Never employ packet sniffer on a local network without checking with an administrator. It's best to try these techniques at home, or on a network you run.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8522588641740201139-3617420289030531689?l=snifferclub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferclub.blogspot.com/feeds/3617420289030531689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://snifferclub.blogspot.com/2008/10/packet-sniffer-brief-introduction.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3617420289030531689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8522588641740201139/posts/default/3617420289030531689'/><link rel='alternate' type='text/html' href='http://snifferclub.blogspot.com/2008/10/packet-sniffer-brief-introduction.html' title='Packet Sniffer, A Brief Introduction'/><author><name>Kevin Zhou</name><uri>http://www.blogger.com/profile/10834917473676154644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/_b4meHPrIBnY/SPSDwVy3zpI/AAAAAAAAAB0/pU8Z7gYwZeo/S220/HIMlogo1.jpg'/></author><thr:total>0</thr:total></entry></feed>
