<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8631624812585403362.post2150648709766905787..comments</id><updated>2009-08-22T14:28:37.644-07:00</updated><title type='text'>Comments on Official DojoSec Blog: What Tool Should Everyone Know?</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.dojosec.com/feeds/2150648709766905787/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8631624812585403362/2150648709766905787/comments/default'/><link rel='alternate' type='text/html' href='http://blog.dojosec.com/2009/04/what-tool-should-everyone-know.html'/><author><name>Marcus J. Carey</name><uri>http://www.blogger.com/profile/07441426999698326334</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8631624812585403362.post-7536716600672622603</id><published>2009-05-06T07:19:00.000-07:00</published><updated>2009-05-06T07:19:00.000-07:00</updated><title type='text'>J.D.,You are right! The only way to determine what...</title><content type='html'>J.D.,&lt;br&gt;&lt;br&gt;You are right! The only way to determine what&amp;#39;s normal is to dive deep into a tool like Wireshark and know what traffic looks like. This can  also be said with log analysis.&lt;br&gt;&lt;br&gt;-MJC</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8631624812585403362/2150648709766905787/comments/default/7536716600672622603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8631624812585403362/2150648709766905787/comments/default/7536716600672622603'/><link rel='alternate' type='text/html' href='http://blog.dojosec.com/2009/04/what-tool-should-everyone-know.html?showComment=1241619540000#c7536716600672622603' title=''/><author><name>Marcus J. Carey</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dojosec.com/2009/04/what-tool-should-everyone-know.html' ref='tag:blogger.com,1999:blog-8631624812585403362.post-2150648709766905787' source='http://www.blogger.com/feeds/8631624812585403362/posts/default/2150648709766905787' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8631624812585403362.post-8893502399385724536</id><published>2009-05-05T01:59:00.000-07:00</published><updated>2009-05-05T01:59:00.000-07:00</updated><title type='text'>Good tool choice!Many people think that Wireshark ...</title><content type='html'>Good tool choice!&lt;br&gt;&lt;br&gt;Many people think that Wireshark is only for when there&amp;#39;s a problem. But one of the good things to do with Wireshark is to get an idea of what&amp;#39;s &amp;quot;normal&amp;quot; with the systems and nets you&amp;#39;re handling.&lt;br&gt;&lt;br&gt;Not just the networks themselves, but also with the typical computers you have connected to the networks. Tap into the network connection (cheap way: get an old ethernet hub, not a switch). &lt;br&gt;&lt;br&gt;Listen in what happens when the computer is powered on, when logging in, doing usual net activities. See what&amp;#39;s talking to what. See what goes by in plaintext that should have been encrypted. An so on.&lt;br&gt;&lt;br&gt;Finally, need a book to help you get started with packet analysis? One that&amp;#39;s a nice starter is &amp;quot;Practical Packet Analysis&amp;quot; from No Starch Press (http://nostarch.com/packet.htm).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8631624812585403362/2150648709766905787/comments/default/8893502399385724536'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8631624812585403362/2150648709766905787/comments/default/8893502399385724536'/><link rel='alternate' type='text/html' href='http://blog.dojosec.com/2009/04/what-tool-should-everyone-know.html?showComment=1241513940000#c8893502399385724536' title=''/><author><name>J.D. Abolins</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.dojosec.com/2009/04/what-tool-should-everyone-know.html' ref='tag:blogger.com,1999:blog-8631624812585403362.post-2150648709766905787' source='http://www.blogger.com/feeds/8631624812585403362/posts/default/2150648709766905787' type='text/html'/></entry></feed>