Ask Your Question

JohnSynAck's profile - activity

2020-07-24 09:54:09 +0000 received badge  Popular Question (source)
2020-04-11 15:23:58 +0000 received badge  Popular Question (source)
2019-08-07 07:58:06 +0000 asked a question extraction of all tcp streams with tshark

extraction of all tcp streams with tshark Hi guys, I would like to know - is there any way to extract all tcp streams fr

2019-08-07 07:48:22 +0000 commented answer deprecated ssl extension

Thank you!

2019-06-02 16:21:55 +0000 marked best answer deprecated ssl extension

HI, I would like to know why ssl.handshake.extensions_elliptic_curve became deprecated..

Moreover, Is there any new field that replace that field?

Thanks, John SynAck.

2019-06-02 13:05:26 +0000 asked a question deprecated ssl extension

deprecated ssl extension HI, I would like to know why ssl.handshake.extensions_elliptic_curve became deprecated.. Moreo

2018-12-19 14:38:43 +0000 asked a question Can't extract MaxmindDb's columns from tshark

Can't extract MaxmindDb's columns from tshark Hi, I compiled tshark on linux without GUI(wireshark 2.6.4). I downloaded

2018-12-19 14:23:14 +0000 commented answer GeoIP with Tshark in linux without GUI

I installed libmaxminddb and recompiled tshark.

2018-12-17 18:50:49 +0000 commented answer GeoIP with Tshark in linux without GUI

It's working, Thank you very much!

2018-12-17 18:50:02 +0000 marked best answer GeoIP with Tshark in linux without GUI

Hi, I compiled the source code of wireshark with out wireshark(it's a vm without GUI). Then i searched for place to put the Maxmind.dat files.. i found some various places to put it in there, but i couldn't extract the geoip.country with tshark. Example of my tshark command: tshark -r test.pcap -T json -e ip.geoip.src_country

The places i tried to put the geoip_db_paths file: /usr/share/wireshark, /usr/local/lib/wireshark, /usr/local/lib64/wireshark, /usr/local/include/wirehshark /usr/local/shark/wireshark

Thanks.

2018-12-17 18:50:02 +0000 received badge  Scholar (source)
2018-12-17 17:45:55 +0000 commented answer GeoIP with Tshark in linux without GUI

If I don't have GeoIP paths there? Do I need to recompile it with other args? Today i compiling wireshark like this: cma

2018-12-17 17:44:40 +0000 commented answer GeoIP with Tshark in linux without GUI

If I don't have GeoIP paths there? Do I need to recompile it with other args? Today i compile wirehsark like this: cmake

2018-12-17 09:18:30 +0000 asked a question GeoIP with Tshark in linux without GUI

GeoIP with Tshark in linux without GUI Hi, I compiled the source code of wireshark with out wireshark(it's a vm without