<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>The Open Source Weblog</title>
<link>http://opensource.weblogsinc.com</link>
<description>The Open Source Weblog</description>
<image>
<url>http://opensource.weblogsinc.com/media/feedlogo.gif</url>
<title>The Open Source Weblog</title>
<link>http://opensource.weblogsinc.com</link>
</image>
<language>en-us</language>
<copyright>Copyright 2009 Blogsmith, LLC. The contents of this feed are available for non-commercial use only.</copyright>
<generator>Blogsmith http://www.blogsmith.com/</generator><item><title>Reasons to use Ethereal as a packet sniffer</title><link>http://opensource.weblogsinc.com/2006/04/03/reasons-to-use-ethereal-as-a-packet-sniffer/</link><guid isPermaLink="true">http://opensource.weblogsinc.com/2006/04/03/reasons-to-use-ethereal-as-a-packet-sniffer/</guid><comments>http://opensource.weblogsinc.com/2006/04/03/reasons-to-use-ethereal-as-a-packet-sniffer/#comments</comments><description><![CDATA[<p>Filed under: <a href="http://opensource.weblogsinc.com/category/security/" rel="tag">security</a>, <a href="http://opensource.weblogsinc.com/category/ethereal/" rel="tag">ethereal</a></p><p>When it comes to sniffing packets, the tool I usually use is Ethereal, a fantastically powerful piece of software.Tony Howlett's book <em>Open Source Security Tools: A Practical Guide to Security Applications</em> covers Ethereal andmany more. You can read a sample chapter, titled "<ahref="http://www.informit.com/articles/article.asp?p=352988&amp;seqNum=1">Network Sniffers: Is Open Source Right forYou?</a>", online. In it, Howlett gives a great list explaining Ethereal's benefits over using straight tcpdump onthe command line. Here's a brief outline of his list. After reading this, go check out the sample chapter &amp; thebook!</p>
<ul>
    <li>Easy to use GUI </li>
    <li>More analytical &amp; statistical options than command line </li>
    <li>Cleaner output format </li>
    <li>Supports over 300 network protocols </li>
    <li>Supports many physical network formats </li>
    <li>Interactively browse &amp; sort captured data </li>
    <li>Save output in a variety of formats </li>
    <li>Display packets with color-coding </li>
    <li>Filter creation GUI makes it easy to create filters </li>
    <li>Follow a TCP stream &amp; view it as a unified whole in ASCII </li>
    <li>Supports many capture programs, libraries, &amp; hardware </li>
    <li>Save sessions in different formats </li>
    <li>Command-line terminal mode </li>
</ul>
<p><em>(Check out all of our posts on <a href="http://opensource.weblogsinc.com/search/?q=firefox">Ethereal</a>, <ahref="http://opensource.weblogsinc.com/search/?q=tcpdump">tcpdump</a>, and <ahref="http://opensource.weblogsinc.com/search/?q=security">security</a>.)</em></p><h6 style="clear: both; padding: 8px 0 0 0; height: 2px; font-size: 1px; border: 0; margin: 0; padding: 0;"></h6><a href="http://opensource.weblogsinc.com/2006/04/03/reasons-to-use-ethereal-as-a-packet-sniffer/" rel="bookmark" title="Permanent link to this entry">Permalink</a>&nbsp;|&nbsp;<a href="http://opensource.weblogsinc.com/forward/604220/" title="Send this entry to a friend via email">Email this</a>&nbsp;|&nbsp;<a href="http://opensource.weblogsinc.com/2006/04/03/reasons-to-use-ethereal-as-a-packet-sniffer/#comments" title="View reader comments on this entry">Comments</a><br />]]></description><dc:creator>Scott Granneman</dc:creator><dc:date>2006-04-03T12:36:00+00:00</dc:date></item></channel></rss>