top of page
Search

Where Did Wireshark's "manuf" File Go?
Prior to Wireshark 4, you would find the manuf file in the Wireshark program directory. The manuf file was a simple text file containing...
Laura Chappell

A Key Wireshark Display Filter Feature is Improved!
One of my favorite features in Wireshark is the ability to click and drag a field from the Packet List pane or Packet Details pane up...
Laura Chappell

Embed TLS Secrets in Trace Files Using Wireshark
Wireshark v4 now has the option to embed TLS secrets into a trace file within the GUI. We could do this before in editcap, but who wants...
Laura Chappell

Wireshark Tip: Filtering on Subnet Addresses
Watch out for this "gotcha" when creating capture filters with subnet masking in CIDR format. DISPLAY FILTERS ALLOW... Display filters...
Laura Chappell

Detect Suspicious Traffic with "TCP Conversation Completeness"
In my last blog entry, I explained how Wireshark calculates TCP Conversation Completeness based on the TCP flags and whether data is seen...
Laura Chappell

Using Wireshark's TCP Conversation Completeness
Wireshark added the TCP conversation completeness measurement to identify elements contained in captured TCP conversations. In this post,...
Laura Chappell

Wireshark's Packet List Sorting Change - What a Pain!
According to Wireshark 4's NEWS text file, "Packet list sorting has been improved." I beg to differ and would like to see this...
Laura Chappell


Wireshark v4 Profile Templates
When Wireshark v4 was released, I received a number of emails complaining about the new layout (Packet Details side-by-side with Packet...
Laura Chappell

Packet Pub Quiz Time!
READY FOR SOME GEEKY FUN? Throughout my career in packet analysis, I've made some great friends with similar interests. Tony Fortunato...
Laura Chappell

WTF? Chrome Killed Access to .pcaps?!
As you may know, Chappell University has a trace file library on an FTP server (accessed via https://www.chappell-university.com/traces)....
Ginny Spicer

Virtual Event Hosting and Video Streaming Troubleshooting
Updated: September 27th, 2020 In March, thousands of IT professionals and students joined us for CORE-IT, a free...
Laura Chappell

Join Me Online at CORE-IT!
CORE-IT is a FREE virtual conference offering training on core tools, protocols, and practices for the IT/cyber industry professionals...
Laura Chappell

The "Legit" DDoS on PG&E
See the legitimate DDoS on PG&Es site after they announced that power would be shut off to upwards of 800,000 customers in October 2019.
Laura Chappell
![Packet Challenge: Look it Up in the Dictionary [100119]](https://static.wixstatic.com/media/fe341d_e2dcd3b59f184d3da881dfeb1c9dc912~mv2.png/v1/fill/w_454,h_341,fp_0.50_0.50,q_95,enc_avif,quality_auto/fe341d_e2dcd3b59f184d3da881dfeb1c9dc912~mv2.webp)
Packet Challenge: Look it Up in the Dictionary [100119]
Packet Challenge: Look it up in the Dictionary - download the trace file and test your skills on this Packet Challenge.
Laura Chappell

HTTP to HTTPS Redirection
Get familiar with HTTP's 301 redirection process to a secure connections. Download the sample trace file and follow along.
Laura Chappell

Troubleshooting SYNs of the Network
After a painfully slow LinkedIn launch, I grabbed the traffic and saw some definite issues in the TCP handshake processes.
Laura Chappell

Customize the Wireshark Expert
Wireshark is a piece of clay. In this blog, Laura teaches you how to customize the Expert Information - an often overlooked feature.
Laura Chappell

GeoIP Mapping in Wireshark
A sexy features in Wireshark, for sure - global mapping based on MaxMind's GeoLite2 geolocation database files! Configure and use it today!
Laura Chappell

Analyze a Malicious HTTP Redirection
It was supposed to be a simple DNS name error trace file... but when I was suddenly redirected to a malicious URL, I went down a rabbit hole
Laura Chappell

Spurious Retransmissions - a Concern?
Should you be concerned about Spurious Retransmissions in a trace file? What triggers these indications and what should you do?
Laura Chappell
bottom of page