<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; wireshark</title>
	<atom:link href="http://hackaday.com/tag/wireshark/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Sun, 12 Feb 2012 08:27:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; wireshark</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Bringing the Shark to the Bee</title>
		<link>http://hackaday.com/2010/12/29/bringing-the-shark-to-the-bee/</link>
		<comments>http://hackaday.com/2010/12/29/bringing-the-shark-to-the-bee/#comments</comments>
		<pubDate>Wed, 29 Dec 2010 14:20:32 +0000</pubDate>
		<dc:creator>James Munns</dc:creator>
				<category><![CDATA[arduino hacks]]></category>
		<category><![CDATA[wireless hacks]]></category>
		<category><![CDATA[packet]]></category>
		<category><![CDATA[wireshark]]></category>
		<category><![CDATA[xbee]]></category>
		<category><![CDATA[zigbee]]></category>
		<category><![CDATA[capture]]></category>
		<category><![CDATA[FreakLabs]]></category>
		<category><![CDATA[Freakduino]]></category>
		<category><![CDATA[libpcap]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=32176</guid>
		<description><![CDATA[Wireshark, a tool recognized universally as being one of the best network analyzers available, has long been used by legitimate network professionals as well as a shadier crowd (and everywhere in between). While useful for analyzing both wired and Wi-Fi traffic, monitoring 802.15.4 protocols (such as Zigbee) have not been a common use in the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=32176&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-32177" title="FreakShark" src="http://hackadaycom.files.wordpress.com/2010/12/freakduino-chibi.jpg" alt="" width="470" height="382" /></p>
<p>Wireshark, a tool recognized universally as being one of the best network analyzers available, has long been used by legitimate network professionals as well as a shadier crowd (and everywhere in between). While useful for analyzing both wired and Wi-Fi traffic, monitoring 802.15.4 protocols (such as Zigbee) have not been a common use in the past. [Akiba] of FreakLabs has brought us <a href="http://freaklabs.org/index.php/Tutorials/Software/Feeding-the-Shark-Turning-the-Freakduino-into-a-Realtime-Wireless-Protocol-Analyzer-with-Wireshark.html">a solution</a> which works around the normal limitations of Wireshark&#8217;s libpcap base, which does not accept simple serial input from most homebrew setups that use FTDI or Arduinos to connect to <a href="http://hackaday.com/2008/11/02/wireless-arduino-programming-with-zigbee/">Zigbee</a> <a href="http://hackaday.com/2009/12/21/hacking-zigbee-chips-cc2430/">devices</a>. Using named pipes and a few custom scripts, [Akiba] has been able to coax Wireshark into accepting input from one of FreakLabs Freakduino boards.</p>
<p>While there are certainly professional wireless analyzing tools out there that connect directly into Wireshark, we at Hackaday love showing off anyone who takes the difficult, cheap, out of the way method of doing things over the neat, expensive, commercial method any day.</p>
<br />Filed under: <a href='http://hackaday.com/category/arduino-hacks/'>arduino hacks</a>, <a href='http://hackaday.com/category/wireless-hacks/'>wireless hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/32176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/32176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/32176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/32176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/32176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/32176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/32176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/32176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/32176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/32176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/32176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/32176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/32176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/32176/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=32176&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/12/29/bringing-the-shark-to-the-bee/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">jahmez</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/12/freakduino-chibi.jpg" medium="image">
			<media:title type="html">FreakShark</media:title>
		</media:content>
	</item>
		<item>
		<title>Wireshark 1.2.0 available</title>
		<link>http://hackaday.com/2009/06/29/wireshark-1-2-0-available/</link>
		<comments>http://hackaday.com/2009/06/29/wireshark-1-2-0-available/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 00:00:42 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[ethereal]]></category>
		<category><![CDATA[geoip]]></category>
		<category><![CDATA[lifehacker]]></category>
		<category><![CDATA[network analysis]]></category>
		<category><![CDATA[openstreetmap]]></category>
		<category><![CDATA[packet sniffer]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=12178</guid>
		<description><![CDATA[Everyone&#8217;s favorite packet sniffer has a new stable release. Wireshark 1.2.0 has a slew of new features. They&#8217;ve included a 64-bit Windows installer and improved their OSX support. A number of new protocols are recognized and filter selection autocompletes. One of the more interesting additions is the combined GeoIP and OpenStreetMap lookups. We&#8217;re excited about [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=12178&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-12179" title="wireshark" src="http://hackadaycom.files.wordpress.com/2009/06/wireshark.jpg" alt="wireshark" width="470" height="371" /></p>
<p>Everyone&#8217;s favorite packet sniffer has a new stable release. <a title="Wireshark: Wireshark 1.2.0 Release Notes" href="http://www.wireshark.org/docs/relnotes/wireshark-1.2.0.html">Wireshark 1.2.0</a> has a slew of new features. They&#8217;ve included a 64-bit Windows installer and improved their OSX support. A number of new protocols are recognized and filter selection autocompletes. One of the more interesting additions is the combined GeoIP and <a href="http://www.openstreetmap.org/">OpenStreetMap</a> lookups. We&#8217;re excited about this new release as Wireshark has proven an indispensable tool in the past for figure out exactly what was going on on our network.</p>
<p>[via <a title="Lifehacker - Wireshark 1.2 Includes 64-Bit Support, Mapping Integration - wireshark" href="http://lifehacker.com/5303805/wireshark-12-includes-64+bit-support-mapping-integration">Lifehacker</a>]</p>
<br />Posted in downloads hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/12178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/12178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/12178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/12178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/12178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/12178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/12178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/12178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/12178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/12178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/12178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/12178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/12178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/12178/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=12178&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/06/29/wireshark-1-2-0-available/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/06/wireshark.jpg" medium="image">
			<media:title type="html">wireshark</media:title>
		</media:content>
	</item>
		<item>
		<title>The Malware Challenge</title>
		<link>http://hackaday.com/2009/01/03/the-malware-challenge/</link>
		<comments>http://hackaday.com/2009/01/03/the-malware-challenge/#comments</comments>
		<pubDate>Sun, 04 Jan 2009 01:00:35 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[anthony lineberry]]></category>
		<category><![CDATA[assembly]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[debug]]></category>
		<category><![CDATA[flexilis]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware challenge]]></category>
		<category><![CDATA[ollydbg]]></category>
		<category><![CDATA[packer]]></category>
		<category><![CDATA[reverse engineer]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7485</guid>
		<description><![CDATA[Our own [Anthony Lineberry] has written up his experience participating in the 2008 Malware Challenge as part of his work for Flexilis. The contest involved taking a piece of provided malware, doing a thorough analysis of its behavior, and reporting the results. This wasn&#8217;t just to test the chops of the researchers, but also to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7485&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7486" title="malware" src="http://hackadaycom.files.wordpress.com/2009/01/malware.jpg" alt="malware" width="450" height="132" /></p>
<p>Our own [Anthony Lineberry] has written up <a title="The Official Flexilis Blog  |  The 2008 Malware Challenge" href="http://blog.flexilis.com/2008/12/the-2008-malware-challenge/">his experience participating in the </a><a title="2008 Malware Challenge" href="http://www.malwarechallenge.info/">2008 Malware Challenge</a> as part of his work for Flexilis. The contest involved taking a piece of provided malware, doing a thorough analysis of its behavior, and reporting the results. This wasn&#8217;t just to test the chops of the researchers, but also to demonstrate to network/system administrators how they could get into malware analysis themselves.</p>
<p>[Anthony] gives a good overview of how he created his entry (a more <a href="http://blog.flexilis.com/wp-content/uploads/2008/12/malwarechallenge2008.pdf">detailed PDF is here</a>). First, he unpacked the malware using <a title="OllyDbg v1.10" href="http://www.ollydbg.de/">Ollydbg</a>. Packers are used to obfuscate the actual malware code so that it&#8217;s harder for antivirus to pick it up. After taking a good look at the assembly, he executed the code. He used <a title="Go deep." href="http://www.wireshark.org/">Wireshark</a> to monitor the network traffic and determine what URL the malware was trying to reach. He changed the hostname to point at an IRC server he controlled. Eventually he would be able to issue botnet control commands directly to the malware. We look forward to seeing what next year&#8217;s contest will bring.</p>
<br />Posted in news, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7485/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7485&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/01/03/the-malware-challenge/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/01/malware.jpg" medium="image">
			<media:title type="html">malware</media:title>
		</media:content>
	</item>
		<item>
		<title>Passive network tap</title>
		<link>http://hackaday.com/2008/09/14/passive-networking-tap/</link>
		<comments>http://hackaday.com/2008/09/14/passive-networking-tap/#comments</comments>
		<pubDate>Sun, 14 Sep 2008 23:27:10 +0000</pubDate>
		<dc:creator>Jason Rollette</dc:creator>
				<category><![CDATA[misc hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[cat5]]></category>
		<category><![CDATA[ethernet]]></category>
		<category><![CDATA[ettercap]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[Passive Network Tap]]></category>
		<category><![CDATA[passive tap]]></category>
		<category><![CDATA[tap]]></category>
		<category><![CDATA[tcpdump]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=3044</guid>
		<description><![CDATA[Making a passive network tap can be an easy and inexpensive undertaking as shown in this Instructable. Passive monitoring or port mirroring is needed because most networks use switches which isolate the network traffic and this does not allow for the entire network to be monitored.  This example uses a single tap, using multiple taps [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=3044&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-3047" title="Network Tap" src="http://hackadaycom.files.wordpress.com/2008/09/f19f5e1fkuq98pdmedium.jpg" alt="" width="450" height="337" /></p>
<p>Making a <a href="http://en.wikipedia.org/wiki/Network_tap" target="_blank">passive network tap</a> can be an easy and inexpensive undertaking as shown in this <a href="http://www.instructables.com/id/Make_a_Passive_Network_Tap/" target="_blank">Instructable</a>. Passive monitoring or port mirroring is needed because most networks use switches which isolate the network traffic and this does not allow for the entire network to be monitored.  This example uses a single tap, using <a href="http://www.sun.com/bigadmin/content/submitted/passive_ethernet_tap.html" target="_blank">multiple taps</a> will provide access to the full-duplex data separately. By using two taps you are able to monitor inbound data that is passed through one tap, and outbound data that is passed through the other tap.  Separate taps are desired because most sniffer software handles half-duplex traffic only and requires two network cards for full-duplex.</p>
<p><span id="more-3044"></span></p>
<p><img class="alignnone size-full wp-image-3060" title="multi tap" src="http://hackadaycom.files.wordpress.com/2008/09/tap.jpg" alt="" width="450" height="291" /></p>
<p>It is easy to insert a passive Ethernet tap inline, as shown in the picture above from a <a href="http://thnetos.wordpress.com/2008/02/22/create-a-passive-network-tap-for-your-home-network/" target="_blank">different multitap project</a>,  simply plug the incoming line into a host port and a patch cable from the other host port to the outgoing port, then verify your connection status. Now connect the Ethernet port of your sniffer computer into either of the tap connectors on the passive Ethernet tap. This tap works by using sniffer applications that put your <a href="http://en.wikipedia.org/wiki/Promiscuous_mode" target="_blank">Ethernet card into promiscuous mode</a>.  This allows you to monitor all traffic on the network not just the traffic directed to your network adapter. After you install your favorite sniffer program, such as <a href="http://www.wireshark.org/" target="_blank">Wireshark</a>, <a href="http://www.snort.org/" target="_blank">Snort</a>, <a href="http://www.tcpdump.org/" target="_blank">TCPDump</a>, <a href="http://www.winpcap.org/windump/" target="_blank">WinDump</a>, or <a href="http://ettercap.sourceforge.net/" target="_blank">Ettercap</a> to name a few,  you are then able to monitor all traffic any way you see fit, like looking for passwords in the video below.</p>
<span style="text-align:center; display: block;"><a href="http://hackaday.com/2008/09/14/passive-networking-tap/"><img src="http://img.youtube.com/vi/7ezGTP99xSw/2.jpg" alt="" /></a></span>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/3044/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/3044/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/3044/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=3044&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/09/14/passive-networking-tap/feed/</wfw:commentRss>
		<slash:comments>22</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jason Rollette</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/09/f19f5e1fkuq98pdmedium.jpg" medium="image">
			<media:title type="html">Network Tap</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/09/tap.jpg" medium="image">
			<media:title type="html">multi tap</media:title>
		</media:content>
	</item>
		<item>
		<title>Detecting ISP throttling</title>
		<link>http://hackaday.com/2008/06/14/detecting-isp-throttling/</link>
		<comments>http://hackaday.com/2008/06/14/detecting-isp-throttling/#comments</comments>
		<pubDate>Sun, 15 Jun 2008 01:50:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[misc hacks]]></category>
		<category><![CDATA[bittorrent]]></category>
		<category><![CDATA[eff]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[isp]]></category>
		<category><![CDATA[netneutrality]]></category>
		<category><![CDATA[networkneutrality]]></category>
		<category><![CDATA[nnma]]></category>
		<category><![CDATA[nnsquad]]></category>
		<category><![CDATA[rtt]]></category>
		<category><![CDATA[throttling]]></category>
		<category><![CDATA[torrent]]></category>
		<category><![CDATA[tunnel]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/14/detecting-isp-throttling/</guid>
		<description><![CDATA[ISPs have recently become very aggressive towards their customers. They&#8217;ve been blocking or altering traffic to prevent you from using specific programs or protocols. Google&#8217;s Senior Policy Director recently stated that they&#8217;re developing tools to allow people to detect ISP interference. A couple other groups have been building tools as well: The Network Neutrality Squad [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2002&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="100" border="0" alt="" src="http://hackadaycom.files.wordpress.com/2008/06/had_torrent.jpg?w=450&#038;h=100" /><br />ISPs have recently become very aggressive towards their customers. They&#8217;ve been blocking or altering traffic to prevent you from using specific programs or protocols. Google&#8217;s Senior Policy Director recently stated that they&#8217;re developing tools to allow people to <a href="http://www.hothardware.com/News/Google_To_Develop_ISP_Throttling_Detector/">detect ISP interference</a>. A couple other groups have been building tools as well: The <a href="http://www.nnsquad.org/">Network Neutrality Squad</a> just released the second beta of their <a href="http://www.nnsquad.org/agent">Network Measurement Agent</a>. The tool currently detects spoofed packets by <a href="http://www.nnsquad.org/nnma-methodology.html">monitoring the round trip time</a> of the connection; early reset packets will have lower than average RTT. If you want to go more in depth, the EFF has published a guide for <a href="http://www.eff.org/wp/detecting-packet-injection">using Wireshark to do the detection</a>. We&#8217;ve even heard rumors of people building tools to tunnel a session inside of one that looks completely different.</p>
<p>[photo: <a href="http://flickr.com/photos/nrkbeta/2305831708/">nrkbeta</a>]</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2002/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2002/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2002/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2002&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/14/detecting-isp-throttling/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had_torrent.jpg" medium="image" />
	</item>
	</channel>
</rss>
