BLOG     |     FORUM

Forum Login

Login is optional - if you want to be notified about responses via email. You can also simply ask a question without logging in.



Just ask your question

No signup required

There is no need to sign up or register to ask a question in the forums.

Just ask your question.

You need to signup if you wish to be notified of answers to your question by email.

Other links

Other ways to reach us

Follow us on Twitter

Follow on twitter

Send us an email

mail us

Welcome, Guest
Please Login or Register.    Lost Password?

Import from ethereal dump
(1 viewing) (1) Guest
All your questions answered real quick by Unleash Networks Engineers.
Go to bottom
Post Reply
Post New Topic
Page: 1
TOPIC: Import from ethereal dump
#87
Import from ethereal dump 5 Years ago Karma: 0
A HTTPS session was captured using etheral and saved the dump. I tried importing the ethereal dump into the unsniff, but i am not able to view the TLS or SSL packet in the window.No display or capture filters applied. As i am testing my own apache SSL server, i am having the servers private key, and also the server IP These had been configured properly in unsniff. Even sometimes i am not able to view the SSL sessions when capturing SSL packets directly using unsniff.

Unsniff ver 1.0.1.1230. Help me..
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Reply Quote
 
#89
Re:Import from ethereal dump 5 Years ago Karma: 0
Ashok,

Do you see any packets at all ? Are they all TCP instead of TLS ? In that case, check if the TCP port 443 is mapped to TLS and TLS port 443 is mapped to HTTP. Use the "Plugins -> Manage Access Points" window.

Regards,
Vivek Rajan
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Reply Quote
 
#91
Re:Import from ethereal dump 5 Years ago Karma: 0
I see the TLS packets as TCP packets. I had already configured the TCP port to 443 and TLS port 443 mapped to HTTP. But still my packets are not in TLS. Even those TCP packets doesnt contain the RL (Record Layer) headers.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Reply Quote
 
#92
Re:Import from ethereal dump 5 Years ago Karma: 0
Thank you very much. I didnt recognise my proxy server. Now configured the proxy port as acces point. Now able to view the packets.Also the packets get decrypted using the server key.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Reply Quote
 
Go to top
Post Reply
Post New Topic
Page: 1