Archive for November 2nd, 2023

Google Chrome OS Version 119.0.6045.106 – steht zum Download bereit

Donnerstag, November 2nd, 2023

Shelly Blu Button – Vorstellung Konfiguration und Test

Donnerstag, November 2nd, 2023

Kalman Filter – understanding extended unscented and particle Kalman Filters

Donnerstag, November 2nd, 2023

Proof Wood – eine Eigenverbrauchsrate bis 90 % ist möglich

Donnerstag, November 2nd, 2023

Bundesamt für Sicherheit in der Informationstechnik (BSI) – aktueller Lagebericht IT Sicherheit im Zeitraum vom 01.06.2022 bis zum 30.06.2023

Donnerstag, November 2nd, 2023

AVM FRITZ!Tech – Portfreigaben bei kaskadierten FRITZ!Box Modellen

Donnerstag, November 2nd, 2023

Anstrengender Alltag als Glaserin – was bekommt man dafür € 2.170,- netto

Donnerstag, November 2nd, 2023

Donnerstag, November 2nd, 2023

Radxa ZERO 3W – a light compact tiny Single Board Computer (SBC)

Donnerstag, November 2nd, 2023

Donnerstag, November 2nd, 2023

Wireshark ‚editcap‘ – is a free tool designed to split capture files (PCAP files) into smaller files based on a criterion

Donnerstag, November 2nd, 2023

Sometimes you might have a very large PCAP file if you are for example debugging a complicated problem and needs to capture PCAP file over night and an overnight captured PCAP file can go up to multi GBs of size and multi millions of captured packets such large PCAP file is extremely heavy to open in a capturing tool like Wireshark

 

C:\LOG>
C:\LOG>dir
Datenträger in Laufwerk C: ist OS Disk
Volumeseriennummer: D28D-8CF5
Verzeichnis von C:\LOG
31.10.2023 16:22 1.216.760.536 nettrace_VA-UI-I-144.pcapng

editcap.exe <Input File> -c <Packets Per Output File>  <Output File>

C:\LOG>C:\“Program Files“\Wireshark\editcap nettrace_VA-UI-I-144.pcapng -c 200000 nettrace_VA-UI-I-144.pcap
C:\LOG>dir
Datenträger in Laufwerk C: ist OS Disk
Volumeseriennummer: D28D-8CF5
Verzeichnis von C:\LOG
31.10.2023 16:22 1.216.760.536 nettrace_VA-UI-I-144.pcapng
02.11.2023 11:28 56.845.460 nettrace_VA-UI-I-144_00000_20231030163943.pcap
02.11.2023 11:28 56.959.340 nettrace_VA-UI-I-144_00001_20231030175505.pcap
02.11.2023 11:28 56.961.532 nettrace_VA-UI-I-144_00002_20231030191049.pcap
02.11.2023 11:28 56.953.260 nettrace_VA-UI-I-144_00003_20231030202730.pcap
02.11.2023 11:28 56.903.404 nettrace_VA-UI-I-144_00004_20231030214358.pcap
02.11.2023 11:28 56.859.180 nettrace_VA-UI-I-144_00005_20231030230045.pcap
02.11.2023 11:28 145.815.708 nettrace_VA-UI-I-144_00006_20231031001645.pcap
02.11.2023 11:28 142.533.688 nettrace_VA-UI-I-144_00007_20231031013000.pcap
02.11.2023 11:28 56.834.224 nettrace_VA-UI-I-144_00008_20231031024439.pcap
02.11.2023 11:28 56.895.304 nettrace_VA-UI-I-144_00009_20231031035822.pcap
02.11.2023 11:28 56.986.836 nettrace_VA-UI-I-144_00010_20231031051452.pcap
02.11.2023 11:28 56.925.696 nettrace_VA-UI-I-144_00011_20231031063053.pcap
02.11.2023 11:28 57.027.476 nettrace_VA-UI-I-144_00012_20231031074754.pcap
02.11.2023 11:28 56.980.096 nettrace_VA-UI-I-144_00013_20231031090351.pcap
02.11.2023 11:28 57.496.864 nettrace_VA-UI-I-144_00014_20231031101943.pcap
02.11.2023 11:28 56.963.820 nettrace_VA-UI-I-144_00015_20231031112227.pcap
02.11.2023 11:28 57.008.272 nettrace_VA-UI-I-144_00016_20231031123841.pcap
02.11.2023 11:28 57.667.560 nettrace_VA-UI-I-144_00017_20231031135407.pcap
02.11.2023 11:28 16.145.108 nettrace_VA-UI-I-144_00018_20231031150521.pcap
C:\LOG>
C:\LOG>C:\“Program Files“\Wireshark\editcap -h
Editcap (Wireshark) 4.0.10 (v4.0.10-0-gf5c7c25a81eb)
Edit and/or translate the format of capture files.
See https://www.wireshark.org for more information.
Usage: editcap [options] … <infile> <outfile> [ <packet#>[-<packet#>] … ]
<infile> and <outfile> must both be present; use ‚-‚ for stdin or stdout.
A single packet or a range of packets can be selected.
Packet selection:
-r keep the selected packets; default is to delete them.
-A <start time> only read packets whose timestamp is after (or equal
to) the given time.
-B <stop time> only read packets whose timestamp is before the
given time.
Time format for -A/-B options is
YYYY-MM-DDThh:mm:ss[.nnnnnnnnn][Z|+-hh:mm]
Unix epoch timestamps are also supported.
Duplicate packet removal:
–novlan remove vlan info from packets before checking for duplicates.
-d remove packet if duplicate (window == 5).
-D <dup window> remove packet if duplicate; configurable <dup window>.
Valid <dup window> values are 0 to 1000000.
NOTE: A <dup window> of 0 with -V (verbose option) is
useful to print MD5 hashes.
-w <dup time window> remove packet if duplicate packet is found EQUAL TO OR
LESS THAN <dup time window> prior to current packet.
A <dup time window> is specified in relative seconds
(e.g. 0.000001).
NOTE: The use of the ‚Duplicate packet removal‘ options with
other editcap options except -V may not always work as expected.
Specifically the -r, -t or -S options will very likely NOT have the
desired effect if combined with the -d, -D or -w.
–skip-radiotap-header skip radiotap header when checking for packet duplicates.
Useful when processing packets captured by multiple radios
on the same channel in the vicinity of each other.
Packet manipulation:
-s <snaplen> truncate each packet to max. <snaplen> bytes of data.
-C [offset:]<choplen> chop each packet by <choplen> bytes. Positive values
chop at the packet beginning, negative values at the
packet end. If an optional offset precedes the length,
then the bytes chopped will be offset from that value.
Positive offsets are from the packet beginning,
negative offsets are from the packet end. You can use
this option more than once, allowing up to 2 chopping
regions within a packet provided that at least 1
choplen is positive and at least 1 is negative.
-L adjust the frame (i.e. reported) length when chopping
and/or snapping.
-t <time adjustment> adjust the timestamp of each packet.
<time adjustment> is in relative seconds (e.g. -0.5).
-S <strict adjustment> adjust timestamp of packets if necessary to ensure
strict chronological increasing order. The <strict
adjustment> is specified in relative seconds with
values of 0 or 0.000001 being the most reasonable.
A negative adjustment value will modify timestamps so
that each packet’s delta time is the absolute value
of the adjustment specified. A value of -0 will set
all packets to the timestamp of the first packet.
-E <error probability> set the probability (between 0.0 and 1.0 incl.) that
a particular packet byte will be randomly changed.
-o <change offset> When used in conjunction with -E, skip some bytes from the
beginning of the packet. This allows one to preserve some
bytes, in order to have some headers untouched.
–seed <seed> When used in conjunction with -E, set the seed to use for
the pseudo-random number generator. This allows one to
repeat a particular sequence of errors.
-I <bytes to ignore> ignore the specified number of bytes at the beginning
of the frame during MD5 hash calculation, unless the
frame is too short, then the full frame is used.
Useful to remove duplicated packets taken on
several routers (different mac addresses for
example).
e.g. -I 26 in case of Ether/IP will ignore
ether(14) and IP header(20 – 4(src ip) – 4(dst ip)).
-a <framenum>:<comment> Add or replace comment for given frame number
Output File(s):
-c <packets per file> split the packet output to different files based on
uniform packet counts with a maximum of
<packets per file> each.
-i <seconds per file> split the packet output to different files based on
uniform time intervals with a maximum of
<seconds per file> each.
-F <capture type> set the output file type; default is pcapng.
An empty „-F“ option will list the file types.
-T <encap type> set the output file encapsulation type; default is the
same as the input file. An empty „-T“ option will
list the encapsulation types.
–inject-secrets <type>,<file> Insert decryption secrets from <file>. List
supported secret types with „–inject-secrets help“.
–discard-all-secrets Discard all decryption secrets from the input file
when writing the output file. Does not discard
secrets added by „–inject-secrets“ in the same
command line.
–capture-comment <comment>
Add a capture file comment, if supported.
–discard-capture-comment
Discard capture file comments from the input file
when writing the output file. Does not discard
comments added by „–capture-comment“ in the same
command line.
Miscellaneous:
-h, –help display this help and exit.
-V verbose output.
If -V is used with any of the ‚Duplicate Packet
Removal‘ options (-d, -D or -w) then Packet lengths
and MD5 hashes are printed to standard-error.
-v, –version print version information and exit.
C:\LOG>

Donnerstag, November 2nd, 2023

Kliniken Ostallgäu-Kaufbeuren – im Jahr 2023 steuert man auf ein Defizit von rund € 9.7 Millionen zu

Donnerstag, November 2nd, 2023

Veeam Backup for AWS – Product Overview

Donnerstag, November 2nd, 2023

Donnerstag, November 2nd, 2023