RE: Packet capture, analysis, regeneration



Mark,
You should take a look at Ethereal (www.ethereal.com). It is
one of the most popular open source network protocol analyzers. We use
it to look at packet traffic from HVAC controllers. You have the
ability to view multiple network protocols and reassemble packets to
examine at their contents.

The program features are listed here
(http://www.ethereal.com/introduction.html#features).

Ethereal has support for multiple platforms if you run Linux, UNIX,
Microsoft, etc.

I would highly recommend that you check it out.

Good Luck,

Adam

-----Original Message-----
From: Mark A. Wireman [mailto:mwireman@xxxxxxxxxxxxxxxx]
Sent: Tuesday, April 18, 2006 4:30 AM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: Packet capture, analysis, regeneration

Has anyone heard of any tools or products that can capture packets,
analyze
them, provide a report on the analysis, and then reassemble to show the
content?

What I have been tasked to do is capture the packets that are generated
by a
custom application, analyze them in terms of size, utilization, and
port,
display a report with the values, and then reassemble them to see if I
can
view the content of the entire stream.

Thanks,
Mark



------------------------------------------------------------------------
------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the
Analyst's
Choice Award from eWeek. As attacks through web applications continue to
rise,
you need to proactively protect your applications from hackers. Cenzic
has the
most comprehensive solutions to meet your application security
penetration
testing and vulnerability management needs. You have an option to go
with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service
can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm
your
results from other product. Contact us at request@xxxxxxxxxx for
details.
------------------------------------------------------------------------
------



------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------



Relevant Pages

  • Re: Penetration Testing a Firewalled Network
    ... The only problem you'll find with manipulating packets to guess the ... internal network is whether or not the firewall itself blocks RCF1918 ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • Re: Packet capture, analysis, regeneration
    ... Has anyone heard of any tools or products that can capture packets, ... Download FREE whitepaper on how a managed service can ... Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. ...
    (Pen-Test)
  • TCPReplay problem
    ... Can we direct tcpreplay to send packets to another machine? ... When it sends out packets on an interface is are they just sent to the next ethernet or is tcpreplay used for testing the machine on which it is installed. ... You have an option to go with a managed service or an enterprise software. ... Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. ...
    (Pen-Test)
  • Re: Using TTL to Locate Hosts
    ... Not sure what you mean with "locate hosts". ... NATing device packets you will see that the IP packets from the device ... vulnerability management needs. ... Download FREE whitepaper on how a managed service can help you: ...
    (Pen-Test)
  • Re: who is doing the request
    ... How to discover what process is doing this request? ... Use Ethereal to analyze the packets sent through the interfaces. ...
    (microsoft.public.windows.server.dns)