Wireshark-users: Re: [Wireshark-users] Anybody seen this before?
From: Matt Bellizzi <mbellizzi@xxxxxxxxxxxxx>
Date: Tue, 9 Jul 2013 18:15:21 +0000
Could it be responses to spoof packets?
From: Martin Visser <martinvisser99@xxxxxxxxx>
Reply-To: Community support list for Wireshark <wireshark-users@xxxxxxxxxxxxx> Date: Tuesday, July 9, 2013 5:16 AM To: "gary@xxxxxxxx" <gary@xxxxxxxx>, Community support list for Wireshark <wireshark-users@xxxxxxxxxxxxx> Subject: Re: [Wireshark-users] Anybody seen this before? When you say that "the only place it can be found is in the capture file" I'm guessing by that you mean it is being sent to an IP or port that is unknown to you. Also just because
something is obscure doesn't mean it isn't normal. For instance, these days a lot of web based applications, are driven by _javascript_, with lots of embedded code - you may well see a lot of references to sites for advertising or other reasons.
Anyway is you want to upload a capture, the most useful place is
http://www.cloudshark.org/ (Just make sure it doesn't contain information you want to keep private)
Also you wish to describe your capture method (is it of traffic to your machine, or is a capture at your router).
Regards, Martin
On 9 July 2013 16:32, GaryT <gary@xxxxxxxx> wrote:
Has anyone seen an activity whereby someone supposedly dumps a load of data on a machine but the only place it can be found is in the capture file? AND much of the same data seems to appear repeatedly. |
- References:
- Re: [Wireshark-users] Anybody seen this before?
- From: Martin Visser
- Re: [Wireshark-users] Anybody seen this before?
- Prev by Date: Re: [Wireshark-users] Anybody seen this before?
- Next by Date: Re: [Wireshark-users] Anybody seen this before?
- Previous by thread: Re: [Wireshark-users] Anybody seen this before?
- Next by thread: Re: [Wireshark-users] Anybody seen this before?
- Index(es):