This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Is it weird that my VM has traffic even though it is not running

0

When I boot up Wireshark I notice that VMWare Network Adapter 1 and 8 have traffic on them (very little, such as: UDP,NBNS, LLMNR, ICMP, MDNS, BROWSER& DHCPv6, only around 60 packets in a minute though.)

asked 12 Jun '16, 10:44

RvBVakama's gravatar image

RvBVakama
6112
accept rate: 0%

1

Each post should have a clear, specific question in the title field. Please rephrase the title as a proper question.

Can you share a capture in a publicly accessible spot, e.g. CloudShark?

(13 Jun '16, 04:43) Jaap ♦

Won't people be able to hack me if I share sensitive data such as the capture? I'm very worried about hacking since I have experienced it way too many times and lost too much data when my PC died many times before :(

(13 Jun '16, 06:52) RvBVakama
1

Have a look at TraceWrangler. It allows to scramble the IP addresses and ports and to strip the payload of packets in a capture file. In this particular case (VM off), I would expect no sensitive contents of the payload, so you only need to obfuscate the IP addresses if any of them are public. If all IP addresses in the capture are private ones, it should be safe to publish it as it is.

(13 Jun '16, 08:29) sindy

Thanks sindy

(13 Jun '16, 08:39) RvBVakama