<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; pcapy</title>
	<atom:link href="http://www.darknet.org.uk/tag/pcapy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Honeysnap &#8211; Pcap Packet Capture File Parsing Tool</title>
		<link>http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/</link>
		<comments>http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 10:01:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[decode packet capture]]></category>
		<category><![CDATA[honey snap]]></category>
		<category><![CDATA[honeysnap]]></category>
		<category><![CDATA[network-forensics]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[pcap data]]></category>
		<category><![CDATA[pcap decoder]]></category>
		<category><![CDATA[pcap file parser]]></category>
		<category><![CDATA[pcap packet parsing tool]]></category>
		<category><![CDATA[pcapy]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1847</guid>
		<description><![CDATA[Honeysnap is designed to be a command-line tool for parsing single or multiple pcap data files and producing a &#8216;first-cut&#8217; analysis report that identifies significant events within the processed data. This presents security analysts with a pre-prepared menu of high value network activity, aimed at focusing manual forensic analysis and saving significant incident investigation time. [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Honeysnap is designed to be a command-line tool for parsing single or multiple pcap data files and producing a &#8216;first-cut&#8217; analysis report that identifies significant events within the processed data. This presents security analysts with a pre-prepared menu of high value network activity, aimed at focusing manual forensic analysis and saving significant incident investigation time. Once you have identified data that interests you, you can then employ other tools for more in depth analysis, such as the Walleye user interface to the Honeywall. Honeysnap is also suitable for manual operation or automation via cron.</p>
<p><strong>Example Functions</strong></p>
<ul>
<li>Packet and connection overview.</li>
<li>Flow extraction of ASCII based communications.</li>
<li>Protocol decode of the more common Internet communication protocols.</li>
<li>Binary file transfer extraction.</li>
<li>Flow summary of inbound and outbound connections.</li>
<li>Keystroke extraction of ver2 and ver 3 Sebek data.</li>
<li>Identification and analysis of IRC traffic, including keyword matching.</li>
</ul>
<p>Version 1.0.6 now decodes the following protocols.</p>
<ul>
<li>DNS</li>
<li>FTP</li>
<li>HTTP</li>
<li>IRC</li>
<li>Socks</li>
<li>Sebek </li>
</ul>
<p>In addtion, the new 1.0.6 version includes</p>
<ul>
<li>Socks proxy traffic stats</li>
<li>User definable filters for the counts</li>
<li>Improved DNS output</li>
<li>Fixed bug in file extraction</li>
<li>A big speed increase in gzip decoding</li>
<li>Print querying IP for DNS decodes</li>
<li>Auto-spotting of IRC traffic on any port</li>
<li>SOCKS decoding</li>
<li>Fix to the truncation of extracted files</li>
<li>Includes magicpy in the distribution to solve the problems caused by the original website going away. </li>
</ul>
<p>You can download Honeysnap here:</p>
<p><a href="https://projects.honeynet.org/honeysnap/attachment/wiki/WikiStart/honeysnap-1.0.6.14.tar.gz">honeysnap-1.0.6.14.tar.gz</a></p>
<p></p>
<p>Or read more <a href=" https://projects.honeynet.org/honeysnap/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Honeysnap+%E2%80%93+Pcap+Packet+Capture+File+Parsing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1847+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/&amp;t=Honeysnap+%E2%80%93+Pcap+Packet+Capture+File+Parsing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/&amp;title=Honeysnap+%E2%80%93+Pcap+Packet+Capture+File+Parsing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/&amp;title=Honeysnap+%E2%80%93+Pcap+Packet+Capture+File+Parsing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/&amp;title=Honeysnap+%E2%80%93+Pcap+Packet+Capture+File+Parsing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/&amp;title=Honeysnap+%E2%80%93+Pcap+Packet+Capture+File+Parsing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Fhoneysnap-pcap-packet-capture-file-parsing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/honeysnap-pcap-packet-capture-file-parsing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pcapy &#8211; Python Interface to LibPcap</title>
		<link>http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/</link>
		<comments>http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/#comments</comments>
		<pubDate>Tue, 18 Dec 2007 10:37:00 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[core-security]]></category>
		<category><![CDATA[libpcap]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[packet handling]]></category>
		<category><![CDATA[packet-crafting]]></category>
		<category><![CDATA[pcapy]]></category>
		<category><![CDATA[Python]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/</guid>
		<description><![CDATA[Pcapy is a Python extension module that interfaces with the libpcap packet capture library. Pcapy enables python scripts to capture packets on the network. Pcapy is highly effective when used in conjunction with a packet-handling package such as Impacket, which is a collection of Python classes for constructing and dissecting network packets. Advantages of Pcapy [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Pcapy is a Python extension module that interfaces with the <a href="http://www.tcpdump.org/">libpcap packet capture library</a>. Pcapy enables python scripts to capture packets on the network. Pcapy is highly effective when used in conjunction with a packet-handling package such as <a href="http://oss.coresecurity.com/projects/impacket.html">Impacket</a>, which is a collection of Python classes for constructing and dissecting network packets.</p>
<p><strong>Advantages of Pcapy</strong></p>
<ul>
<li>Works with Python threads.</li>
<li>Functions in both UNIX with libpcap and Windows with WinPcap.</li>
<li>Provides a simpler Object Oriented API.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>A Python interpreter. Versions 2.1.3 and higher.</li>
<li>A C++ compiler. GCC G++ 2.95, as well as Microsoft Visual Studio 6.0 or MSVC 2003 depending on the Python version.</li>
<li>A Libpcap 0.9.3 or newer. Windows users should have installed WinPcap 4.0 or newer. </li>
</ul>
<p>Download Pcapy here:</p>
<p><strong>Source code</strong></p>
<p>Latest stable release (0.10.5) &#8211; <a href="http://oss.coresecurity.com/repo/pcapy-0.10.5.tar.gz">gzip&#8217;d tarball</a> or <a href="http://oss.coresecurity.com/repo/pcapy-0.10.5.zip">zip file</a></p>
<p><strong>Win32 binaries</strong> &#8211; Pick the appropriate Python or WinPcap version.</p>
<p>Latest release (0.10.5) &#8211; <a href="http://oss.coresecurity.com/repo/pcapy-0.10.5.win32-py2.5.exe">Windows installer</a> – Python 2.5 and WinPcap 4.0.<br />
0.10.4 &#8211; <a href="http://oss.coresecurity.com/repo/pcapy-0.10.4.win32-py2.4.exe">Windows installer</a> – Python 2.4 and WinPcap 3.1.</p>
<p></p>
<p>Or read more <a href="http://oss.coresecurity.com/projects/pcapy.html">here</a> and the documentation is <a href="http://oss.coresecurity.com/pcapy/doc/pt01.html">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Pcapy+%E2%80%93+Python+Interface+to+LibPcap+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D720+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/&amp;t=Pcapy+%E2%80%93+Python+Interface+to+LibPcap" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/&amp;title=Pcapy+%E2%80%93+Python+Interface+to+LibPcap" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/&amp;title=Pcapy+%E2%80%93+Python+Interface+to+LibPcap" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/&amp;title=Pcapy+%E2%80%93+Python+Interface+to+LibPcap" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/&amp;title=Pcapy+%E2%80%93+Python+Interface+to+LibPcap" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F12%2Fpcapy-python-interface-to-libpcap%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/12/pcapy-python-interface-to-libpcap/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

