Free Wireshark Training Course Online

Take a free Wireshark Jumpstart training class online at http://www.chappellseminars.com/.

Thursday, August 19, 2010

Official Exam Prep Guide Hits Amazon!

Visit www.wiresharkbook.com/epg to see sample pages.
Visit the
Amazon Marketplace page to purchase.
---------------------------------------------------------------------------------------------------------------

It's been a busy time teaching webinars covering the Wireshark Certified Network
Analyst Exam and then the Exam Prep Guide being released (earlier than
expected) on Amazon.

Watch the recorded Wireshark Certified Network Analyst video at
www.wiresharktraining.com/certification.

The new Exam Prep Guide is designed to help you evaluate your readiness to
take the Wireshark Certified Network Analyst (WCNA) Exam.

Thanks to all of our reviewers and good luck to all of you who have registered to
take the Exam at
www.webassessor.com/pai!

Laura Chappell
---------------------------------------------------------------------------------------------------------------
More information and to download the Exam Information Pack, visit
www.wiresharktraining.com/certification.

Wednesday, August 11, 2010

Wireshark Certification Exam is Released!

Download the Exam Information Pack
Download the Step-by-Step Registration Information Pack.

Register - Free webinar: Become a Wireshark Certified Network Analyst
---------------------------------------------------------------------------------------------------------------

I am thrilled to announce that the Wireshark Certified Network Analyst Exam is
NOW AVAILABLE ! The Exam is available globally in a proctored format through
Kryterion. Currently the Exam is only available in English.

The Wireshark Certification Exam was designed to confirm
individual competencies in using Wireshark to locate the
cause of network problems (poor performance or security-
related) and confirm your knowledge of TCP/IP network
communications in general.

The Exam is based on the thirty-three areas of study defined in the Exam Focus
and Content section of this document. The four primary areas covered in this
Exam are:

  • Wireshark Functionality
  • TCP/IP Network Communications
  • Network Troubleshooting
  • Network Security

To earn the Wireshark Certified Network Analyst status, you must pass a single
exam—the WCNA-100x Exam (version 100.1 is the current version).

Register for the Exam
The Wireshark Certified Network Analyst Exam is available at hundreds of testing
centers around the world. You can take your Exam at a KRYTERION High-stake
Online Secure Testing (HOST) location near you. To locate a local testing center,
visit
www.kryteriononline.com/host_locations.

The Wireshark Certified Network Analyst Exam is a closed-book Exam consisting
of 100 questions. The Exam time limit is 2 hours (120 minutes). Exam questions
are in true/false or multiple choice format (there is only one correct answer for
each multiple choice question). Many of the questions include a Wireshark
screen image.

Exam Pricing
The Wireshark Certified Network Analyst Exam cost is USD 299. The Wireshark
Certified Network Analyst Exam Practice Exam (online) cost is USD 29.

Pass/Fail Grading
The Wireshark Certified Network Analyst Exam is graded on a pass/fail basis.
Passing scores are set by using statistical analysis. At the completion of the
Exam, Candidates receive a score report along with a score breakout by Exam
section.

How to Register for Your Exam
Register for the proctored Wireshark Certified Network Analyst Exam online at
www.webassessor.com/pai.

Step-by-step Exam Registration instructions and complete Exam Preparation
recommendations are available at
www.wiresharktraining.com/certification.

The Official Exam Prep Guide will be on Amazon around August 23rd - learn more
at
www.wiresharkbook.com/epg.

Thanks to all of you who have been so patient as we rewrote, redesigned and
redeveloped the Exam. We are excited to see Wireshark become more popular
each month and hope the Wireshark Certified Network Analyst designation
becomes a de facto certification for all IT professionals.

Laura Chappell
---------------------------------------------------------------------------------------------------------------
More information and to download the Exam Information Pack, visit
www.wiresharktraining.com/certification.

Wednesday, July 21, 2010

Wireshark Exam Prep Guide in Final Editing!

Update: The book has gone to the printers. We expect it to be available on
Amazon around August 23rd. For more information, visit
www.wiresharkbook.com.

Yes - this blog has been quiet for a bit - I've been putting in an unreal amount of
time prepping the Wireshark Certified Network Analyst Exam and the new
Wireshark Certified Network Analyst Official Exam Prep Guide (shown above).

After writing the Wireshark Network Analysis: Official Wireshark Certified Network
Analyst Study Guide, we had talked about building a prep guide to provide a feel
for the questions on the Exam.

The result is a 202-page Exam Prep Guide that covers over 300 questions in the
book and over 300 questions in both timed and untimed exam format on the
accompanying CD.

The Exam is about ready to release - both the Exam and Exam Prep Guide
should be announced on the same day (get ready). Measure and validate your
analysis skills using the Exam Prep Guide and taking the Wireshark Certified
Network Analyst Exam!

More information on the Exam release and requirements will be coming up over
at www.wiresharktraining.com/certification.

For more information on the Wireshark Certified Network
Analyst Official Exam Prep Guide, visit
www.wiresharkbook.com/epg.

Are you ready? Check out the Exam Prep questions below:

Note: If Amazon.com doesn't have the Wireshark Network Analysis book in stock,
check out our Amazon Marketplace page.

The MAC name resolution process resolves the first 3 bytes of the
MAC address to the OUI value contained in Wireshark’s manuf file.

__ True
__ False

The first two packets of a single TCP handshake process can be
used to determine the long term average round trip latency time
between hosts.

__ True
__ False


The display filter tcp.analysis.flags shows all packets that
have the TCP Reset bit set to 1.

__ True
__ False


ICMP Destination Unreachable messages sent in response to an
FTP connection attempt indicate the FTP port is likely firewalled.

__ True
__ False


Which TCP setting must be enabled in order to use the
tcp.analysis.flags display filter?

__ A. Try Heuristic Subdissectors First
__ B. Analyze TCP Sequence Numbers
__ C. Allow Subdissector to Reassemble TCP Streams
__ D. Window Scaling and Relative Sequence Numbers


Which Calc value is best suited to graphing the IO rate using
tcp.len?
__ A. SUM(*)
__ B. MIN(*)
__ C. LOAD(*)
__ D. MAX(*)


Enjoy life... one bit at a time.

Laura

Answers: True (that's the purpose of the manuf file), False (you need more than
just a single SYN, SYN/ACK to figure out the long-term average RTT), False (this
filter shows packets marked as retransmissions, window zero, checksum errors,
etc. - not TCP reset packets), True (if the port were open, we'd see a SYN/ACK, if it
were closed we'd see a RST - an ICMP response indicates a likely firewall
fantastic Wireshark display filter), A (you want to count up all the TCP data - not
just know the minimum or maximum values for the time period - the LOAD(*) is
used for time values).

Wednesday, June 2, 2010

Google's Secure Search... Not So Secure?

Watch two new videos examining Google searches using HTTP and HTTPS - now
available at www.wiresharkbook.com/coffee. Note that the trace files used in the
video are in the download section of that site.

As a follow-up to last week's "Peeking at Google's Secure Search Beta Traffic"
blog, I did a bit more poking around in the secure search traffic after getting this
question via Twitter.

Here are the steps seen in the trace file called google-https-
cachedlink_plus_sitelink.pcap over at the wiresharkbook.com
download page.

1. Access https://www.google.com
2. Search for "hacking cisco ip phones"
3. Click on the cached link for one result (a blog page)
4. Click on one of the links on that blog page

In analyzing the traffic, I noticed the following:

  • It takes 3 TLS/SSL connections just to load the Google secure search
    page.
  • When I clicked on the cached link I connected to Google's web cache site
    (webcache.googleusercontent.com CNAME googlehosted.l.google.com).
  • My original search terms were contained in clear text in the GET query to
    Google's cache server.
  • My original search terms were also contained in the packets generated to
    the Symantec secure browsing server.
  • When I clicked one of the links on the cached page, I connected to the
    target website and provided my referral information (including my search
    terms)

This is NOT secure searching if you click a cached link in
Google's "secure" search beta.

Heck - apply the display filter http.request.method == "GET" && frame
contains "hacking"
and see how many times my search term showed up in
the traffic.

So... what's the point of Google's secure search? Google states the following:

"With Google search over SSL, you can have an end-to-end encrypted search
solution between your computer and Google. This secured channel helps protect
your search terms and your search results pages from being intercepted by a
third party. This provides you with a more secure and private search experience."

Wow - that's as misleading as my son saying his homework is "mostly finished."
Am I not a third-party? Maybe a bit of clarity is warranted here, Googlites!

Google - I suggest you kill the cached link feature on your secure search page.
Otherwise you aren't offering any secrecy to unsuspecting folks who might click
on those links.

Enjoy life... one bit at a time!

Laura

Tuesday, May 25, 2010

Peeking at Google's Secure Search Beta Traffic

Watch the new video comparing Google searches using HTTP and HTTPS -
now available at www.wiresharkbook.com/coffee. Note that the two trace files
used in the video are in the download section of that site.

If you haven't been following Google lately, you might have missed their "secure
search" announcement. It's HTTPS-based, but don't think you're totally secure
from prying eyes when you web browse (also see Chapter 23 of the Wireshark
Network Analysis book for details on HTTPS analysis).

Secure Search Doesn't Hide Target Browsing
Just because your Google search process is running with HTTPS and is
encrypted, this doesn't mean that when you click that link your browsing
session that follows is encrypted. Some chatter last week indicated that
Google's "secure search" somehow protected you more than it really does.
Sure, your browsing session is encrypted, but the minute you click on an HTTP
link, I can read the DNS query issued (if any) and the HTTP session to the target
site.

Yes, Removing the Referrer Data will Screw up Analytics
One "side effect" of Google's secure search option is that when you click on the
target link from the Google's secure search page, the referrer information is not
sent to the target - they can't tell from whence you came. Oh, boy - this really is
going to mess up the analytics.

Analytics-hounds are going to freak out on this one!

Get an All Access Pass at
here and check out the video detailing the two Google
search processes.

Enjoy life... one bit at a time!

Laura

Sunday, May 2, 2010

Talking Tech with RunAs Radio

Last week I had the chance to talk with Richard Campbell and Greg Hughes of
RunAs Radio. You can listen
here.

Don't know about RunAs Radio?
RunAs Radio started back in 2007 and offers weekly radio shows primarily for a
Microsoft-centric audience. My episode #160! I got interested in RunAs Radio
when I learned that Andy Malone had been interviewed recently on RunAs Radio
(I'm on a Cloud Computing panel with Andy at TechEd next month).

Grey Hair, Fire Extinguishers, Needles in a Haystack, Vegas and More
Although the session started with a reference to my ever-increasing grey hairs
and the need for a fire extinguisher in the kitchen, Richard pushed towards the
issues related to wireless analysis. "It's been abused so much."

We chatted about "jacked up access points" and saturation of the WLAN
environment in a Vegas casino.

Cool Topics/Presenters
Visit the RunAs Radio archives to check out the other 159 programs. Here are
some that I really enjoyed listening to.

  • Doug Toombs - free tools - although he missed Wireshark for some
    unknown reason - at least he got Nmap in there. Listen here.
  • Nick Simons - he's the guy that killed Clippy - Nick talks about some free
    tools for IT pros. I know you all love free tools! Listen here.
  • Steve Riley - now over at Amazon's Cloud Computing division - it's
    always interesting to listen to Steve. Listen here.


Go check out the podcasts at RunAs Radio and enjoy life... one bit at a time!

Laura

The "Death of" Series

I've been having a great time working on some really lousy networks! You too?! What a coincidence!

As conference season approaches (June), I've just finished writing up my draft presentations. I'll be starting a series of presentations inspired by the Dexter series on Showtime. As we've run through the entire season just recently, the
images of death were first and foremost on my mind when I started sketching out these presentations.

DEATH OF A NETWORK: Identify the Hidden Cause of Lousy Network Performance
I'm going to have fun with this one! This is my "finger pointing" session and I have some major pointing to do! I'm not going to sugar coat some of the more recent causes of pathetic performance and I'll be showing the trace files used
to nail down who's really killing the network.

DEATH OF SECURITY: Breached Hosts/Stolen Data/IP Espionage
A long conversation with a buddy at a 3-letter agency gave me some ideas of what to share in this session. We'll talk some recent case stuff before looking at suspicious traffic and have a heart-to-heart about the methods in which your
network security may fail you.

ADD SOME HUMOR TOO...
It's not all death and doom though. I added some "ugly network" humor in there. In fact I'm going to have difficulty keeping a straight face as I walk through the traffic of a certain hip phone that exudes attitude on the network. Hmmm.... who could that be?

ALL ACCESS PASS MEMBERS
I'll be recording these "Death of" presentations for our All Access Pass members, so get a membership if you want to
catch these new presentations without heading to a conference.

Of course, I won't be serving wine or beer, but you'll probably remember the information better that way!

Enjoy life... one bit at a time!

Laura