Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Testing IDS with tcpreplay |
|---|---|
| Date: | Wed, 15 Feb 2006 22:18:35 -0800 |
On 2/15/06, Prashant Khandelwal <prashant@juniper.net> wrote:
<snip> Obviously the biggest limitation of tcpreplay is it doesn't come with a library of pcaps. Maybe one of these days I can figure out the logistics to make that happen and encourage people to actually submit pcaps (which people tend to worry might have some kind of confidential IP in them) rather then just leech off everyone else. If anyone has any bright ideas I'd love to hear them. </snip> Well if its matter of hiding ip address and sensitive information then, I guess tests which are run with private ip address in labs can be captured and shared... just a thought...
Well IP addresses are only a part of it. Rewriting a pcap stream to change the IP addresses to be RFC1918 is actually pretty easy (tcpreplay can do it for you if you'd like). But some protocols embed the server FQDN/IP in the application layer (HTTP's Host header for example). And things like usernames and passwords are probably a bit more worrisome and tend to be more difficult to edit in a pcap file. Overall, unless you're capturing traffic in a dedicated lab environment, most organizations (at least the ones I've talked to) wouldn't be happy with wide distribution of traffic captures from inside or at the perimeter of their network. -- Aaron Turner http://synfin.net/ ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Testing IDS with tcpreplay, Prashant Khandelwal |
|---|---|
| Next by Date: | Re: IPS Reliability/Availability, Martin Roesch |
| Previous by Thread: | RE: Testing IDS with tcpreplay, Prashant Khandelwal |
| Next by Thread: | RE: Testing IDS with tcpreplay, Bhaarath |
| Indexes: | [Date] [Thread] [Top] [All Lists] |