<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2773536350893785230.post5093010586746475725..comments</id><updated>2010-08-02T11:20:15.506+02:00</updated><category term='WebApp'/><category term='Mobile'/><category term='Incident Handling'/><category term='PenTest'/><category term='GSM'/><category term='iphone'/><category term='OWASP'/><category term='Wi-Fi'/><category term='SMB'/><category term='tower location'/><category term='Vulnerability'/><category term='wireshark SMB'/><category term='SSL'/><category term='GSM/UMTS/GPRS/EDGE/HSPA/LTE'/><category term='signal'/><category term='GPRS'/><category term='Tool'/><title type='text'>Comments on Taddong: Capturing SMB Files with Wireshark</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.taddong.com/feeds/5093010586746475725/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html'/><author><name>Monica Salas</name><uri>http://www.blogger.com/profile/14278327913222052048</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2773536350893785230.post-5849823735876811203</id><published>2010-08-02T11:20:15.506+02:00</published><updated>2010-08-02T11:20:15.506+02:00</updated><title type='text'>Our functionality is included in the development v...</title><content type='html'>Our functionality is included in the development version of Wireshark from revision 33229 on. Compilation has been tested by wireshark team, including windows compilation. &lt;br /&gt;It is not included in an stable version of Wireshark yet, so no precompiled windows version of wireshark that includes the export-object-smb functionality is available to download from wireshark home page yet. &lt;br /&gt;&lt;br /&gt;At the moment, you can have this functionality for windows environments, by building wireshark in windows from source code.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/5849823735876811203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/5849823735876811203'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html?showComment=1280740815506#c5849823735876811203' title=''/><author><name>Jose Pico</name><uri>http://www.blogger.com/profile/07792388506501969140</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html' ref='tag:blogger.com,1999:blog-2773536350893785230.post-5093010586746475725' source='http://www.blogger.com/feeds/2773536350893785230/posts/default/5093010586746475725' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1180491439'/></entry><entry><id>tag:blogger.com,1999:blog-2773536350893785230.post-4834222515644185079</id><published>2010-08-02T11:09:52.291+02:00</published><updated>2010-08-02T11:09:52.291+02:00</updated><title type='text'>Andy,

thank you very much for your comment.

Most...</title><content type='html'>Andy,&lt;br /&gt;&lt;br /&gt;thank you very much for your comment.&lt;br /&gt;&lt;br /&gt;Most past and current SMB implementations don&amp;#39;t support traffic encryption by themselves. As an alternative (if that is your case), you could use another layer to protect privacy of SMB messages:&lt;br /&gt;- You can use a network layer protection, such IPSec&lt;br /&gt;- You can also use SSL or TLS at transport layer to transport SMB protocol messages&lt;br /&gt;- Or you could use an application that encrypts the traffic on a file before sending it over the network&lt;br /&gt;&lt;br /&gt;Depending on the environment, you should evaluate the best available option. One obvious thing to take care of is that the option you choose must be available for implementation at the client and the server side.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;Jose</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/4834222515644185079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/4834222515644185079'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html?showComment=1280740192291#c4834222515644185079' title=''/><author><name>Jose Pico</name><uri>http://www.blogger.com/profile/07792388506501969140</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html' ref='tag:blogger.com,1999:blog-2773536350893785230.post-5093010586746475725' source='http://www.blogger.com/feeds/2773536350893785230/posts/default/5093010586746475725' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1180491439'/></entry><entry><id>tag:blogger.com,1999:blog-2773536350893785230.post-3308813303107403673</id><published>2010-07-09T05:06:02.027+02:00</published><updated>2010-07-09T05:06:02.027+02:00</updated><title type='text'>The plug-in is very cool, I compiled wireshark wit...</title><content type='html'>The plug-in is very cool, I compiled wireshark with eo_smb_cb in BT4, and was able to capture the transfer files. it is really amazing. you guys are so great!&lt;br /&gt;Just one question: how can we fix this vulnerability? thanks,&lt;br /&gt;&lt;br /&gt;Andy</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/3308813303107403673'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/3308813303107403673'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html?showComment=1278644762027#c3308813303107403673' title=''/><author><name>Andy</name><uri>http://andyinmatrix.blogspot.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html' ref='tag:blogger.com,1999:blog-2773536350893785230.post-5093010586746475725' source='http://www.blogger.com/feeds/2773536350893785230/posts/default/5093010586746475725' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-960856502'/></entry><entry><id>tag:blogger.com,1999:blog-2773536350893785230.post-5346939058554745074</id><published>2010-07-07T18:46:21.010+02:00</published><updated>2010-07-07T18:46:21.010+02:00</updated><title type='text'>Is it included in the windows version as well?</title><content type='html'>Is it included in the windows version as well?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/5346939058554745074'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/5346939058554745074'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html?showComment=1278521181010#c5346939058554745074' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html' ref='tag:blogger.com,1999:blog-2773536350893785230.post-5093010586746475725' source='http://www.blogger.com/feeds/2773536350893785230/posts/default/5093010586746475725' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-302593342'/></entry><entry><id>tag:blogger.com,1999:blog-2773536350893785230.post-2035384219621365010</id><published>2010-06-17T00:28:09.585+02:00</published><updated>2010-06-17T00:28:09.585+02:00</updated><title type='text'>Additional note: the compilation for Windows have ...</title><content type='html'>Additional note: the compilation for Windows have also been verified and fixed by Wireshark team.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/2035384219621365010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/2035384219621365010'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html?showComment=1276727289585#c2035384219621365010' title=''/><author><name>Jose Pico</name><uri>http://www.blogger.com/profile/07792388506501969140</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html' ref='tag:blogger.com,1999:blog-2773536350893785230.post-5093010586746475725' source='http://www.blogger.com/feeds/2773536350893785230/posts/default/5093010586746475725' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1180491439'/></entry><entry><id>tag:blogger.com,1999:blog-2773536350893785230.post-8226312560846412205</id><published>2010-06-16T23:04:09.247+02:00</published><updated>2010-06-16T23:04:09.247+02:00</updated><title type='text'>The SMB export object functionality has been inclu...</title><content type='html'>The SMB export object functionality has been included in Wireshark development trunk, so there is no need to apply the patch anymore. &lt;br /&gt;That means that if you download and compile in linux the latest Wireshark svn trunk you will have the SMB plugin included in it.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/8226312560846412205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/8226312560846412205'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html?showComment=1276722249247#c8226312560846412205' title=''/><author><name>Jose Pico</name><uri>http://www.blogger.com/profile/07792388506501969140</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html' ref='tag:blogger.com,1999:blog-2773536350893785230.post-5093010586746475725' source='http://www.blogger.com/feeds/2773536350893785230/posts/default/5093010586746475725' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1180491439'/></entry><entry><id>tag:blogger.com,1999:blog-2773536350893785230.post-7707765002338054608</id><published>2010-06-14T20:09:22.019+02:00</published><updated>2010-06-14T20:09:22.019+02:00</updated><title type='text'>Hi Ceres,

the last version of the patch has been ...</title><content type='html'>Hi Ceres,&lt;br /&gt;&lt;br /&gt;the last version of the patch has been compiled against version 1.5.0 (SVN Rev 33208 from /trunk) of Wireshark.&lt;br /&gt;&lt;br /&gt;The process of including this functionality in an stable version of Wireshark is in progress. You may follow this process through wireshark bug database bug id 4451: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4451&lt;br /&gt;&lt;br /&gt;There you will find the history of updates of this patch and from now on, we will also be including the revision number that we use to compile the patch.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;Jose</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/7707765002338054608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/7707765002338054608'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html?showComment=1276538962019#c7707765002338054608' title=''/><author><name>Jose Pico</name><uri>http://www.blogger.com/profile/07792388506501969140</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html' ref='tag:blogger.com,1999:blog-2773536350893785230.post-5093010586746475725' source='http://www.blogger.com/feeds/2773536350893785230/posts/default/5093010586746475725' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1180491439'/></entry><entry><id>tag:blogger.com,1999:blog-2773536350893785230.post-2684430375179062079</id><published>2010-06-11T16:09:31.724+02:00</published><updated>2010-06-11T16:09:31.724+02:00</updated><title type='text'>I cannot compile wireshark with eo_smb_cb

My wire...</title><content type='html'>I cannot compile wireshark with eo_smb_cb&lt;br /&gt;&lt;br /&gt;My wireshark is wireshark-1.4.0rc1&lt;br /&gt;&lt;br /&gt;Linux is Mandriva 2008.1 with custom openssl and zlib&lt;br /&gt;&lt;br /&gt;I have en error&lt;br /&gt;&lt;br /&gt;gtk/libui.a(menus.o):(.data+0x14b8): undefined reference to `eo_smb_cb&amp;#39;&lt;br /&gt;collect2: ld returned 1 exit status&lt;br /&gt;gmake[2]: *** [wireshark] Error 1&lt;br /&gt;gmake[2]: *** Waiting for unfinished jobs....&lt;br /&gt;&lt;br /&gt;Many thanks&lt;br /&gt;&lt;br /&gt;ceres</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/2684430375179062079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2773536350893785230/5093010586746475725/comments/default/2684430375179062079'/><link rel='alternate' type='text/html' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html?showComment=1276265371724#c2684430375179062079' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.taddong.com/2010/05/capturing-smb-files-with-wireshark.html' ref='tag:blogger.com,1999:blog-2773536350893785230.post-5093010586746475725' source='http://www.blogger.com/feeds/2773536350893785230/posts/default/5093010586746475725' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2014690956'/></entry></feed>
