<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>postIt &#187; wireshark</title>
	<atom:link href="https://lakm.us/postit/tag/wireshark/feed/" rel="self" type="application/rss+xml" />
	<link>https://lakm.us/postit</link>
	<description>Post-It sticky notes with PasteBin sense</description>
	<lastBuildDate>Thu, 02 Jan 2025 01:33:57 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=4.0.18</generator>
	<item>
		<title>Wireshark filter out watchdog (DWR/SWA)  &#8230;</title>
		<link>https://lakm.us/postit/2010/10/wireshark-filter-out-watchdog-dwrswa/</link>
		<comments>https://lakm.us/postit/2010/10/wireshark-filter-out-watchdog-dwrswa/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 08:04:54 +0000</pubDate>
		<dc:creator><![CDATA[Arif]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://xp-racy.lan/postit/?p=105</guid>
		<description><![CDATA[Wireshark filter out watchdog (DWR/DWA) and CER/CEA diameter and diameter.cmd.code != 280 and diameter.cmd.code != 257 Filter out accounting request/answer (ACR/ACA) and destination IP diameter.cmd.code == 271 &#038;&#038; ip.dst == 10.201.63.37]]></description>
				<content:encoded><![CDATA[<p>Wireshark filter out watchdog (DWR/DWA) and CER/CEA<br />
<code>diameter and diameter.cmd.code != 280 and diameter.cmd.code != 257</code><br />
Filter out accounting request/answer (ACR/ACA) and destination IP<br />
<code>diameter.cmd.code == 271 &#038;&#038; ip.dst == 10.201.63.37</code></p>
]]></content:encoded>
			<wfw:commentRss>https://lakm.us/postit/2010/10/wireshark-filter-out-watchdog-dwrswa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>In Wireshark
If coloring of TCP analysi &#8230;</title>
		<link>https://lakm.us/postit/2010/08/in-wiresharkif-coloring-of-tcp-analysi/</link>
		<comments>https://lakm.us/postit/2010/08/in-wiresharkif-coloring-of-tcp-analysi/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:52:38 +0000</pubDate>
		<dc:creator><![CDATA[Arif]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://xp-racy.lan/postit/?p=102</guid>
		<description><![CDATA[In Wireshark If coloring of TCP analysis is disturbing i.e. black higlights, uncheck the &#8220;Validate the TCP checksum if possible&#8221; in Edit > Preferences > Protocols > TCP]]></description>
				<content:encoded><![CDATA[<p>In Wireshark<br />
If coloring of TCP analysis is disturbing i.e. black higlights, uncheck the &#8220;Validate the TCP checksum if possible&#8221; in Edit > Preferences > Protocols > TCP</p>
]]></content:encoded>
			<wfw:commentRss>https://lakm.us/postit/2010/08/in-wiresharkif-coloring-of-tcp-analysi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>For SCAPv1 diameter TCP port in Wireshar &#8230;</title>
		<link>https://lakm.us/postit/2010/08/for-scapv1-diameter-tcp-port-in-wireshar/</link>
		<comments>https://lakm.us/postit/2010/08/for-scapv1-diameter-tcp-port-in-wireshar/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 03:28:53 +0000</pubDate>
		<dc:creator><![CDATA[Arif]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[diameter]]></category>
		<category><![CDATA[port]]></category>
		<category><![CDATA[SCAPv1]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://xp-racy.lan/postit/?p=101</guid>
		<description><![CDATA[For SCAPv1 diameter TCP port in Wireshark Edit > Preferences > Protocols must be altered from standard 3868 to 1812]]></description>
				<content:encoded><![CDATA[<p>For SCAPv1 diameter TCP port in Wireshark Edit > Preferences > Protocols must be altered from standard 3868 to 1812</p>
]]></content:encoded>
			<wfw:commentRss>https://lakm.us/postit/2010/08/for-scapv1-diameter-tcp-port-in-wireshar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dictionaries for diameter /usr/share/wi &#8230;</title>
		<link>https://lakm.us/postit/2010/08/dictionaries-for-diameterusrsharewi/</link>
		<comments>https://lakm.us/postit/2010/08/dictionaries-for-diameterusrsharewi/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 03:06:33 +0000</pubDate>
		<dc:creator><![CDATA[Arif]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[diameter]]></category>
		<category><![CDATA[dictionary]]></category>
		<category><![CDATA[SCAPv1]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://xp-racy.lan/postit/?p=99</guid>
		<description><![CDATA[Dictionaries for diameter /usr/share/wireshark/diameter After backup original dictionaries, to use SCAPv1 of Ericsson&#8217; proprietary diameter protocol, replace them with: dcca.xml ericsson.xml nasreq.xml tgpp.xml dictionary.dtd imscxdx.xml pps.xml vfe.xml dictionary.xml mobileipv4.xml sunping.xml Original files were chargecontrol.xml Ericsson.xml imscxdx.xml sip.xml TGPPRx.xml dictionary.dtd etsie2e4.xml mobileipv4.xml sunping.xml TGPPSh.xml dictionary.xml gqpolicy.xml nasreq.xml TGPPGmb.xml]]></description>
				<content:encoded><![CDATA[<p>Dictionaries for diameter<br />
<code>/usr/share/wireshark/diameter</code><br />
After backup original dictionaries, to use SCAPv1 of Ericsson&#8217; proprietary diameter protocol, replace them with:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="bash" style="font-family:monospace;">dcca.xml        ericsson.xml    nasreq.xml   tgpp.xml
dictionary.dtd  imscxdx.xml     pps.xml      vfe.xml
dictionary.xml  mobileipv4.xml  sunping.xml</pre></td></tr></table></div>

<p>Original files were</p>
<pre>
chargecontrol.xml  Ericsson.xml  imscxdx.xml     sip.xml      TGPPRx.xml
dictionary.dtd     etsie2e4.xml  mobileipv4.xml  sunping.xml  TGPPSh.xml
dictionary.xml     gqpolicy.xml  nasreq.xml      TGPPGmb.xml
</pre>
]]></content:encoded>
			<wfw:commentRss>https://lakm.us/postit/2010/08/dictionaries-for-diameterusrsharewi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>tcp.flags == 0x18 and ip.src == 10.201.6 &#8230;</title>
		<link>https://lakm.us/postit/2010/03/tcp-flags-0x18-and-ip-src-10-201-6/</link>
		<comments>https://lakm.us/postit/2010/03/tcp-flags-0x18-and-ip-src-10-201-6/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 12:14:53 +0000</pubDate>
		<dc:creator><![CDATA[Arif]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[wireshark]]></category>
		<category><![CDATA[XML-RPC]]></category>

		<guid isPermaLink="false">http://xp-racy.lan/postit/?p=53</guid>
		<description><![CDATA[tcp.flags == 0x18 and ip.src == 10.201.62.249 and ip.dst == 10.201.62.78 Filter out PSH ACK (flags 0x18: &#8220;Push&#8221; and &#8220;Acknowledgement&#8221;). In UCIP XML-RPC, it carries response from AIR server e.g. the following stream HTTP/1.1 401 Access to /Air denied for this user ... Content-Length: 366 Content-Type: text/html Date: Fri, 26 Mar 2010 07:52:55 GMT Server]]></description>
				<content:encoded><![CDATA[<p><code>tcp.flags == 0x18 and ip.src == 10.201.62.249 and ip.dst == 10.201.62.78 </code></p>
<p>Filter out PSH ACK (flags 0x18: &#8220;Push&#8221; and &#8220;Acknowledgement&#8221;). In UCIP XML-RPC, it carries response from AIR server e.g. the following stream</p>
<p><code>HTTP/1.1 401 Access to /Air denied for this user ...<br />
Content-Length: 366<br />
Content-Type: text/html<br />
Date: Fri, 26 Mar 2010 07:52:55 GMT<br />
Server</code></p>
]]></content:encoded>
			<wfw:commentRss>https://lakm.us/postit/2010/03/tcp-flags-0x18-and-ip-src-10-201-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Filter out initial SYN (flags 0x02) of T &#8230;</title>
		<link>https://lakm.us/postit/2010/03/filter-out-initial-syn-flags-0x02-of-t/</link>
		<comments>https://lakm.us/postit/2010/03/filter-out-initial-syn-flags-0x02-of-t/#comments</comments>
		<pubDate>Sun, 21 Mar 2010 00:03:24 +0000</pubDate>
		<dc:creator><![CDATA[Arif]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://xp-racy.lan/postit/?p=44</guid>
		<description><![CDATA[Filter out initial SYN (flags 0x02) of TCP connection from specific source and destination: tcp.flags == 0x02 and ip.src == 10.201.62.78 and ip.dst == 10.201.62.249 A series of sync packets will appear as: 1 2 3 4 5 6 7 No. Time Source Destination Protocol Info 1 0.000000 10.201.62.78 10.201.62.249 TCP 53161 &#62; 10010 &#91;SYN&#93; [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Filter out initial SYN (flags 0x02) of TCP connection from specific source and destination:<br />
<code>tcp.flags == 0x02 and ip.src == 10.201.62.78 and ip.dst == 10.201.62.249</code></p>
<p>A series of sync packets will appear as:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
</pre></td><td class="code"><pre class="bash" style="font-family:monospace;">No.     Time        Source                Destination           Protocol Info
      <span style="color: #000000;">1</span> <span style="color: #000000;">0.000000</span>    10.201.62.78          10.201.62.249         TCP      <span style="color: #000000;">53161</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000;">10010</span> <span style="color: #7a0874; font-weight: bold;">&#91;</span>SYN<span style="color: #7a0874; font-weight: bold;">&#93;</span> <span style="color: #007800;">Seq</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">Win</span>=<span style="color: #000000;">49640</span> <span style="color: #007800;">Len</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">MSS</span>=<span style="color: #000000;">1460</span> <span style="color: #007800;">WS</span>=<span style="color: #000000;">0</span>
      <span style="color: #000000;">4</span> <span style="color: #000000;">0.001124</span>    10.201.62.78          10.201.62.249         TCP      <span style="color: #000000;">53162</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000;">10010</span> <span style="color: #7a0874; font-weight: bold;">&#91;</span>SYN<span style="color: #7a0874; font-weight: bold;">&#93;</span> <span style="color: #007800;">Seq</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">Win</span>=<span style="color: #000000;">49640</span> <span style="color: #007800;">Len</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">MSS</span>=<span style="color: #000000;">1460</span> <span style="color: #007800;">WS</span>=<span style="color: #000000;">0</span>
      <span style="color: #000000;">7</span> <span style="color: #000000;">0.001556</span>    10.201.62.78          10.201.62.249         TCP      <span style="color: #000000;">53163</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000;">10010</span> <span style="color: #7a0874; font-weight: bold;">&#91;</span>SYN<span style="color: #7a0874; font-weight: bold;">&#93;</span> <span style="color: #007800;">Seq</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">Win</span>=<span style="color: #000000;">49640</span> <span style="color: #007800;">Len</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">MSS</span>=<span style="color: #000000;">1460</span> <span style="color: #007800;">WS</span>=<span style="color: #000000;">0</span>
     <span style="color: #000000;">16</span> <span style="color: #000000;">0.006334</span>    10.201.62.78          10.201.62.249         TCP      <span style="color: #000000;">53164</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000;">10010</span> <span style="color: #7a0874; font-weight: bold;">&#91;</span>SYN<span style="color: #7a0874; font-weight: bold;">&#93;</span> <span style="color: #007800;">Seq</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">Win</span>=<span style="color: #000000;">49640</span> <span style="color: #007800;">Len</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">MSS</span>=<span style="color: #000000;">1460</span> <span style="color: #007800;">WS</span>=<span style="color: #000000;">0</span>
     <span style="color: #000000;">20</span> <span style="color: #000000;">0.009590</span>    10.201.62.78          10.201.62.249         TCP      <span style="color: #000000;">53165</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000;">10010</span> <span style="color: #7a0874; font-weight: bold;">&#91;</span>SYN<span style="color: #7a0874; font-weight: bold;">&#93;</span> <span style="color: #007800;">Seq</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">Win</span>=<span style="color: #000000;">49640</span> <span style="color: #007800;">Len</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">MSS</span>=<span style="color: #000000;">1460</span> <span style="color: #007800;">WS</span>=<span style="color: #000000;">0</span>
     <span style="color: #000000;">24</span> <span style="color: #000000;">0.011687</span>    10.201.62.78          10.201.62.249         TCP      <span style="color: #000000;">53166</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000;">10010</span> <span style="color: #7a0874; font-weight: bold;">&#91;</span>SYN<span style="color: #7a0874; font-weight: bold;">&#93;</span> <span style="color: #007800;">Seq</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">Win</span>=<span style="color: #000000;">49640</span> <span style="color: #007800;">Len</span>=<span style="color: #000000;">0</span> <span style="color: #007800;">MSS</span>=<span style="color: #000000;">1460</span> <span style="color: #007800;">WS</span>=<span style="color: #000000;">0</span></pre></td></tr></table></div>

<p>In the above specific case, multiple ports i.e. 53163, 53162, etc. is starting conversation with port 10010 by sending out sync packets.</p>
]]></content:encoded>
			<wfw:commentRss>https://lakm.us/postit/2010/03/filter-out-initial-syn-flags-0x02-of-t/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
