First time here? Check out the FAQ!

Ask Your Question
0

Anonymizing pcaps for sharing/analysis

asked Apr 20 '1

HappySailor gravatar image

Hi there I'd like to share a PCAP file for comments. How can I strip MAC address info and data so that it can safely shared on this boeard?

Preview: (hide)

1 Answer

Sort by » oldest newest most voted
0

answered Apr 20 '1

SYN-bit gravatar image

Have a look at this blog-post by @Jasper (who wrote Tracewrangler)

Preview: (hide)
link

Comments

Thanks!.........

HappySailor gravatar imageHappySailor ( Apr 20 '1 )

Tracewrangler works great. The only limitation I have bumped into is that it can only remove single VLAN tag. Use editcap to remove multiple VLAN tags.

BigFatCat gravatar imageBigFatCat ( Apr 20 '1 )

Glad to hear it worked great for you and maybe @Jasper can add Q-in-Q (or rather, recursive) vlan scrubbing :-)

SYN-bit gravatar imageSYN-bit ( Apr 21 '1 )

I'll have to check into that - Tracewrangler can parse stacked VLAN tags but maybe I forgot to actually add code to remove them...

Jasper gravatar imageJasper ( Apr 21 '1 )

Why would people want to anonymise VLAN tags? Frankly, why would people want also to remove private ip addresses? Is there any reason why you would want to anonymise anything else than mac address and payload?

HappySailor gravatar imageHappySailor ( Apr 21 '1 )

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: Apr 20 '1

Seen: 1,341 times

Last updated: Apr 21 '21