{"id":76,"date":"2005-05-20T01:29:39","date_gmt":"2005-05-20T08:29:39","guid":{"rendered":"http:\/\/www.wilyness.com\/blog\/?p=76"},"modified":"2005-05-20T01:29:39","modified_gmt":"2005-05-20T08:29:39","slug":"anyone-good-with-ethereal","status":"publish","type":"post","link":"https:\/\/www.wilyness.com\/blog\/?p=76","title":{"rendered":"Anyone good with Ethereal?"},"content":{"rendered":"<p>A couple of months ago, our organization&#8217;s network was hit by&#8230; something.  I couldn&#8217;t really tell if it was a DOS attack or &#8220;just&#8221; a rapidly spreading virus.  All I knew was that my DHCP requests were barely getting through, and all other traffic seemed to be being dropped.  The cheap ethernet switch I had its activity lights flickering faster than I had ever seen, and for all ports (broadcast packets?).<\/p>\n<p>This made me pretty disgruntled with our network ops(shouldn&#8217;t this be stopped at the WAN router), but I didn&#8217;t think whining about it would do any good.  So I fired up Knoppix, since it has Ethereal built-in, and I obviously didn&#8217;t have the connectivity to download a port of it otherwise.<\/p>\n<p>Mind you, I&#8217;ve never used Ethereal before, but it seemed like a good chance to play with it.  So I had it gather a couple of traces off the network.  FYI, 30 second traces were weighing in at around 13MB, so, do the math, and you can get a feel for how much junk was coming through my 10Mbps link.  Anyway, I didn&#8217;t make a whole lot of sense of it, but if anyone wants to take a peek at one of the traces and email\/post-a-comment, s\/he is welcome to it.<\/p>\n<p><a href=\"http:\/\/www.wilyness.com\/blog\/share\/paloverde.31sec.ethereal.zip\">Download Ethereal trace (.zip)<\/a><\/p>\n<p>Because of spam considerations, if you wish to email me, please do through the &#8220;Contact Daniel&#8221; link on the blog&#8217;s main page.  Thanks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A couple of months ago, our organization&#8217;s network was hit by&#8230; something. I couldn&#8217;t really tell if it was a DOS attack or &#8220;just&#8221; a rapidly spreading virus. All I knew was that my DHCP requests were barely getting through, &hellip;<\/p>\n<p class=\"read-more\"><a href=\"https:\/\/www.wilyness.com\/blog\/?p=76\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[4],"tags":[],"_links":{"self":[{"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/76"}],"collection":[{"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=76"}],"version-history":[{"count":0,"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/76\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=76"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=76"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wilyness.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=76"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}