This event has ended!

View current events hosted by Atlanta HTCIA

WireShark One-Day Wireless Training

Monday, August 16, 2010 from 8:00 AM to 4:00 PM (ET)

Atlanta, GA

WireShark One-Day Wireless Training

Ticket Information

Ticket Type Remaining Sales End Price Fee Quantity
HTCIA Member 2 tickets Ended $50.00 $0.00
Non-Member 2 tickets Ended $150.00 $0.00

Event Details

This hands-on, one-day WireShark training features Betty DuBois as the instructor. You'll learn the tool from top to bottom, and probably have fun doing it. Students will also receive an AirPCAP Tx card to take home as part of the class ($298 list price).

Note: if you already have an AirPCAP, please indicate this when registering. Please be respectful if you have a card already... the more cards of their own people bring, the more people can attend the class.

IMPORTANT: You must bring your own Windows laptop to this training. You must also have WireShark installed and configured. Instructions on how to do this, plus network tutorials (for those of you who need to brush up; basic networking skills are required) will be emailed to you when you register.

Agenda

  • Introductions
  • Wireshark overview
  • Data Capture

    • Capture Interfaces

      • Ethernet

      • Wireless with AirPcap

    • Capture options

    • Capture filters

  • Data Analysis

    • Statistics

      • Summary Information

      • Protocol hierarchy

      • Conversations

      • Endpoints

    • Basic display filtering

    • Reassembly

    • Coloring rules

    • Decryption

      • Wireless

      • SSL

      • Kerberos

    • Command Line Tools

      • tshark

Labs will be done throughout the day. Labs will include live traffic captures and canned trace files.

Labs:

  1. Capture HTTP traffic from a mirror port

  2. Capturing FTP traffic from a tap

  3. Capturing HTTP traffic via AirPcap

  4. Capture specific user’s only

  5. Filter based on various protocols from the Conversations and Endpoints lists

  6. Create multiple display filters and save them to a profile

  7. Reassemble files transferred via FTP

  8. Reassemble files transferred the HTTP

  9. Reassemble VoIP files

  10. Import and edit a color rules set and save to profile

  11. Decrypt WEP traffic

  12. Decrypt WPA-PSK traffic

  13. Decrypt SSL traffic

  14. Use tshark to capture large trace files

  15. Use tshark to parse out a single host’s data from a 2 gig trace file

  16. Rogue Access Point Hunt - Team Competition