<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DEQAQn45eCp7ImA9WxNWF0Q.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853</id><updated>2009-10-17T09:19:03.020-07:00</updated><title>Inside Laura's Lab</title><subtitle type="html">A look inside Laura Chappell's protocol analysis lab and ramblings on her conference travels and onsite packet-level life. A bit of humor, a bit of technology - 10 bits in all.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://laurachappell.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://laurachappell.blogspot.com/" /><link rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>37</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="self" href="http://feeds.feedburner.com/InsideLaurasLab" type="application/atom+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry gd:etag="W/&quot;CEMBQH8yfSp7ImA9WxNWFUk.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-3286204729789594219</id><published>2009-08-25T10:33:00.000-07:00</published><updated>2009-10-14T10:47:31.195-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-14T10:47:31.195-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="window frozen" /><category scheme="http://www.blogger.com/atom/ns#" term="filter" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><title>Enough is Enough! No More Broken Windows</title><content type="html">&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_v5vcOkUEGvc/StYM9zRrCrI/AAAAAAAAAIY/kLJR8HkdATw/s1600-h/brokenwindow.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 175px; height: 114px;" src="http://3.bp.blogspot.com/_v5vcOkUEGvc/StYM9zRrCrI/AAAAAAAAAIY/kLJR8HkdATw/s320/brokenwindow.jpg" alt="" id="BLOGGER_PHOTO_ID_5392511859698633394" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;No... I'm not Microsoft-bashing (today)... not really. After all, this issue is seen on other operating systems a&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;s well. I recorded information about this in the things that perplexes many new and experienced analysts.&lt;br /&gt;&lt;br /&gt;You may be aware th&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;at W&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;ireshark has an Expert Info Composite entry for "Window is Full" and "Frozen Window" but unfortunately, this condition can be occurring &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;on your network without Wireshark catching it.&lt;br /&gt;&lt;br /&gt;You can set up a &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;butt-ugly color filter and a display filter to alert you to this condition. &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;Let me explain...&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_v5vcOkUEGvc/StYNiXdUIUI/AAAAAAAAAIg/iN8AyZG5rPA/s1600-h/downloadbad.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 478px; height: 139px;" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/StYNiXdUIUI/AAAAAAAAAIg/iN8AyZG5rPA/s320/downloadbad.png" alt="" id="BLOGGER_PHOTO_ID_5392512487886430530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In the picture above, I've added column for the receive window size value set in the TCP &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;headers of each packet. It's a custom column using the syntax tcp.window_size. I also added a column for the tcp.len value so I can see how much data is contained in each packet.&lt;br /&gt;&lt;br /&gt;Notice in packet 361 that 10.0.52.164 is advertising a window size of 2,920 bytes - enough for two 1460-byte segments to fill as Wireshark notes in packet 363 [TCP Window Full]. The full receive buffer leads the client to begin advertising a receive window size of &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;0. Ok... duh... We can spot that one easily!&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_v5vcOkUEGvc/StYN23I9WAI/AAAAAAAAAIo/mOBGNkMPg3U/s1600-h/downloadgood.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 493px; height: 135px;" src="http://1.bp.blogspot.com/_v5vcOkUEGvc/StYN23I9WAI/AAAAAAAAAIo/mOBGNkMPg3U/s320/downloadgood.png" alt="" id="BLOGGER_PHOTO_ID_5392512839988369410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now look at this screenshot. This delay is caused by a window sized problem as well - but this time the window size field didn't go alt the way down to zero - its at 536 (packet 374). That's too small for the queued up TCP segment at the other side so you might as well have said "shut up" with a window zero setting.&lt;br /&gt;&lt;br /&gt;So what can we do about this? How can we easily see that we are having this problem when Wireshark doesn't have an Expert Notification for this? Aha! Here's where your butt-uglies come into play. Make a butt ugly filter for:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;(tcp.window_size &lt; reset ="=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_v5vcOkUEGvc/StYORQxat9I/AAAAAAAAAIw/KXka2al6-E0/s1600-h/filtter.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 130px;" src="http://4.bp.blogspot.com/_v5vcOkUEGvc/StYORQxat9I/AAAAAAAAAIw/KXka2al6-E0/s320/filtter.png" alt="" id="BLOGGER_PHOTO_ID_5392513293545551826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Check out the Trace File Analysis: TCP In-Depth course for more information on working with TCP traffic!&lt;br /&gt;&lt;br /&gt;Laura&lt;br /&gt;Enjoy life one bit at a time!&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-3286204729789594219?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/zGB0zZ29dj0" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3286204729789594219?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3286204729789594219?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/zGB0zZ29dj0/enough-is-enough-no-more-broken-windows.html" title="Enough is Enough! No More Broken Windows" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_v5vcOkUEGvc/StYM9zRrCrI/AAAAAAAAAIY/kLJR8HkdATw/s72-c/brokenwindow.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/08/enough-is-enough-no-more-broken-windows.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcCQnYyeCp7ImA9WxNWFUk.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-2657033862782765393</id><published>2009-08-17T09:25:00.000-07:00</published><updated>2009-10-14T10:41:03.890-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-14T10:41:03.890-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="stilettos" /><category scheme="http://www.blogger.com/atom/ns#" term="wi-spy" /><title>Sexy Spread Spectrum Signals</title><content type="html">&lt;span style="font-size:85%;"&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_v5vcOkUEGvc/StYJwbLcisI/AAAAAAAAAIQ/O9CmU3XGaCM/s1600-h/stilettos_copy.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 121px; height: 186px;" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/StYJwbLcisI/AAAAAAAAAIQ/O9CmU3XGaCM/s320/stilettos_copy.png" alt="" id="BLOGGER_PHOTO_ID_5392508331356883650" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;In the WLAN Analysis 101 course last month, I showed the effects of a cheap 2.4GHz phone on the wireless network by knocking myself off the network during my live video feed. Duh... I hope it made a point.&lt;br /&gt;&lt;br /&gt;If I hadn't been picking up the RF signals around me, the death of my network connection would have been a mystery. After all, the cutoff was so sudden and folks in other locations around weren't having any problems at all.&lt;br /&gt;&lt;br /&gt;The live course viewers saw the &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;sudden spike in the signal as I'd told them to watch the Chanalyzer Spectral View. begin to climb near channel 1 and then SCREECH! The video came to a halt and my voice (fed through VoIP on my end) became scratchy and my words almost impossible to decipher.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_v5vcOkUEGvc/StX82I-rYFI/AAAAAAAAAII/PfAGV8Z8qbM/s1600-h/chanalyzer1.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 126px;" src="http://3.bp.blogspot.com/_v5vcOkUEGvc/StX82I-rYFI/AAAAAAAAAII/PfAGV8Z8qbM/s320/chanalyzer1.jpg" alt="" id="BLOGGER_PHOTO_ID_5392494135899545682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-family:arial;"&gt;&lt;br /&gt;The figure above shows their view at the time I attacked myself! Wow! What a hot, my connection to the online seminar engine, it felt like real life - this is what really  happens in the WLAN world - and we got to experience it together.&lt;br /&gt;&lt;br /&gt;I love looking at the Chanalyzer Spectral View - it consists of time across the X axis and frequency/channel across the Y axis. The color coding is based on signal amplitude. The closer to red, the stronger the signal. Vertical stripping indicates a consistent signal on a specific frequency. Manipulating the time controller at the bottom of the Chanalyzer window enables me to focus in on a specific area of time for a clearer picture.&lt;br /&gt;&lt;br /&gt;The Chanalyzer/Wi-Spy Adapter products are some of the sexiest products that have come around in the industry in a long time. Displaying the live RF signals around me prior to making a presentation at a conference is like wearing a hot pair of steel stilettos. Attention-getting and very sexy (in a sick and twisted geeky way).&lt;br /&gt;&lt;br /&gt;We've now partnered with the Metageek folks on the upcoming WLAN Analysis 101 course on September 10th -  if you purchase the 2.4x or DBx Wi-Spy adapters, you'll get into the live class for free. If you already own their products, you should receive a 50% off coupon via their newsletter. As soon as we record the course, you'll also receive one-week unlimited access to the recorded course.&lt;br /&gt;&lt;br /&gt;It's a good time to get the adapter... c'mon... you know you want one! You can order the products at www.metageek.net.&lt;br /&gt;&lt;br /&gt;Laura&lt;br /&gt;Enjoy life one bit at a time!&lt;/span&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-2657033862782765393?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/x6d-kHMgRFY" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2657033862782765393?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2657033862782765393?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/x6d-kHMgRFY/in-wlan-analysis-101-course-last-month.html" title="Sexy Spread Spectrum Signals" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_v5vcOkUEGvc/StYJwbLcisI/AAAAAAAAAIQ/O9CmU3XGaCM/s72-c/stilettos_copy.png" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/08/in-wlan-analysis-101-course-last-month.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcNRn4yfyp7ImA9WxNWFUk.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-1801320865493712718</id><published>2009-08-11T09:19:00.000-07:00</published><updated>2009-10-14T10:41:37.097-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-14T10:41:37.097-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ethereal" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><title>Ethereal is Dead!</title><content type="html">&lt;span class="text" style=";font-family:arial;font-size:85%;"  &gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;Gerald Combs created Ethereal over 11 years ago when his boss wouldn't buy  him a brand spanking new Sniffer box - something about budgets and all... so  Gerald told his Sniffer rep that he was going to write his own packet sniffing tool.  While that Sniffer rep was still rolling around laughing, Gerald started working on  Ethereal.&lt;br /&gt;&lt;br /&gt;The name? Yeah - the name Ethereal was always an issue - how do you  pronounce it? Ethereal (&lt;/span&gt;&lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.chappellseminars.com/files/etherealwrong.wav" target="_blank"&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;&lt;span style="line-height: 15px;"&gt;play wav&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;) or Ethereal (&lt;/span&gt;&lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.chappellseminars.com/files/etherealright2.wav" target="_blank"&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;&lt;span style="line-height: 15px;"&gt;play wav&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;)? Many a late night has  been spent huddled over pizzas in the cabling closet debating that issue. The  answer - Ethereal (&lt;/span&gt;&lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.chappellseminars.com/files/etherealright2.wav"&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;&lt;span style="line-height: 15px;"&gt;play wa&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="text" style=";font-family:arial;font-size:85%;"  &gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.chappellseminars.com/files/etherealright2.wav"&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;&lt;span style="line-height: 15px;"&gt;v&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;).&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;Notes:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span class="text" style=";font-family:arial;font-size:85%;"  &gt;&lt;ul style="margin: 0px 0px 0px 40px; padding: 0pt;"&gt;&lt;li style="line-height: 0px; color: rgb(0, 0, 0);"&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.wireshark.org/download.html" target="_blank"&gt;&lt;span style="color: rgb(204, 102, 0);"&gt;&lt;span style="line-height: 15px;"&gt;Download&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt; th&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;e latest version &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;of Wireshark&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="line-height: 0px; color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;Watch a video on how to set up the GeoIP feature at &lt;/span&gt;&lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.securitytube.net/Setting-up-GeoIP-to-Track-IP-Address-Locations-in-Wireshark-video.aspx" target="_blank"&gt;&lt;span style="color: rgb(204, 102, 0);"&gt;&lt;span style="line-height: 15px;"&gt;SecuityTube&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="line-height: 0px; color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;Peruse through the videos, trace files and podcasts on our &lt;/span&gt;&lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.screencast.com/users/laurachappell" target="_blank"&gt;&lt;span style="color: rgb(204, 102, 0);"&gt;&lt;span style="line-height: 15px;"&gt;media roll&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="line-height: 0px; color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;Register for the live or recorded &lt;/span&gt;&lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.chappellseminars.com/s-wireshark101.html"&gt;&lt;span style="color: rgb(204, 102, 0);"&gt;&lt;span style="line-height: 15px;"&gt;Wireshark Jumpstart&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt; course.&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;&lt;br /&gt;It surprises me to find many folks haven't moved up to Wireshark - it is, after all,  the successor to Ethereal. The same developers, the same creator, the same  base code set, the same development directory structure. I can only assume  those folks also have 8-track tape players and beam with pride when talking about  their 'vinyl collection.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_v5vcOkUEGvc/StX6M_B3rGI/AAAAAAAAAHg/ZUaUarHxIwM/s1600-h/ethereal.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 89px;" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/StX6M_B3rGI/AAAAAAAAAHg/ZUaUarHxIwM/s320/ethereal.jpg" alt="" id="BLOGGER_PHOTO_ID_5392491229830687842" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="text" style=";font-family:arial;font-size:85%;"  &gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;For fun, I went to visit the old eth&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="text" style=";font-family:arial;font-size:85%;"  &gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;ereal.com website - I thought the old Ethereal  website was taken down ages ago, but imagine that NIS is still reaping some  benefit from all the misguided hits. Looking at the stats in Alexa was pretty  interesting - you can see the dramatic move to Wireshark at the end of the first  quarter of 2008 - but what the heck is happening with Ethereal.com in 2009?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_v5vcOkUEGvc/StX6fZrDmcI/AAAAAAAAAHo/UNI-ZoabGqs/s1600-h/ethereal-visits-graph.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 197px;" src="http://4.bp.blogspot.com/_v5vcOkUEGvc/StX6fZrDmcI/AAAAAAAAAHo/UNI-ZoabGqs/s320/ethereal-visits-graph.jpg" alt="" id="BLOGGER_PHOTO_ID_5392491546220403138" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="text" style=";font-family:arial;font-size:85%;"  &gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="text" style=";font-family:arial;font-size:85%;"  &gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Why are people still even hitting that site? Is everyone writing a blog entry about  'dead' software projects? Did some of my old articles and courses get reissued?  Who are these Neanderthals walking among us?&lt;br /&gt;&lt;br /&gt;It's time to upgrade to Wireshark folks. Wireshark v1.2.1 was released just a few  weeks ago and fixed numerous bugs in the v1.2 release. There are still a few  uglies in there, but would you rather be in a car that has a window that slowly rolls  up or take a bicycle on that long drive along the network analysis road?&lt;br /&gt;&lt;br /&gt;So perhaps today is the day to throw away those old bell bottom jeans and that  mood ring (and perhaps dump those Shaper Image gift cards and Clear cards&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="text" style=";font-family:arial;font-size:85%;"  &gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt; as  well).&lt;br /&gt;&lt;br /&gt;Come on - get with the times! Oh... one more thing - and you pronounce Wireshark  like this (&lt;/span&gt;&lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.chappellseminars.com/files/wireshark.mp3"&gt;&lt;span style="color: rgb(204, 102, 0);"&gt;&lt;span style="line-height: 15px;"&gt;play mp3&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;&lt;span style="line-height: 15px;"&gt;).&lt;br /&gt;&lt;br /&gt;Laura&lt;br /&gt;Enjoy life one bit at a time!&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_v5vcOkUEGvc/StX616QPuvI/AAAAAAAAAHw/nFUwIVWKhNQ/s1600-h/ethereal-visitors.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 132px;" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/StX616QPuvI/AAAAAAAAAHw/nFUwIVWKhNQ/s320/ethereal-visitors.jpg" alt="" id="BLOGGER_PHOTO_ID_5392491932923443954" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-1801320865493712718?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/cTyKTQs_QWs" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/1801320865493712718?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/1801320865493712718?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/cTyKTQs_QWs/gerald-combs-created-ethereal-over-11.html" title="Ethereal is Dead!" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_v5vcOkUEGvc/StX6M_B3rGI/AAAAAAAAAHg/ZUaUarHxIwM/s72-c/ethereal.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/08/gerald-combs-created-ethereal-over-11.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IFQHw_fCp7ImA9WxJaFUw.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-3214610984454735223</id><published>2009-08-05T15:07:00.000-07:00</published><updated>2009-08-05T15:31:51.244-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-05T15:31:51.244-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="embedded os" /><category scheme="http://www.blogger.com/atom/ns#" term="os fingerprinting" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><title>Out of Sight, Out of Mind?</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_v5vcOkUEGvc/SnoIJx2L-mI/AAAAAAAAAHY/iIKfHSYCyZI/s1600-h/sonosite+m-turbo+ultrasound+copy.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 149px; height: 150px;" src="http://3.bp.blogspot.com/_v5vcOkUEGvc/SnoIJx2L-mI/AAAAAAAAAHY/iIKfHSYCyZI/s400/sonosite+m-turbo+ultrasound+copy.png" alt="" id="BLOGGER_PHOTO_ID_5366610870057826914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:arial;" &gt;Embedded OS Security Issues&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;&lt;br /&gt;This month seems to be "medical industry month" around here. My email has been loaded up with various hospitals and medical facilities. One of the topics that is hot right now is 'embedded OS' security issues. For example, the three devices shown in the image above all contain Microsoft embedded operating systems - Windows Embedded CE. (See http://www.microsoft.com/windowsembedded/en-us/default.mspx)&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;How many hosts on your network support an embedded OS? Is the vendor keeping those hosts up-to-date with patches and security fixes? An interesting question... this is a great reason to run OS fingerprinting against the range of IP addresses supported on your network (with permission of course) to find out where the addressable devices are. Listen to the network traffic and check out the endpoint listing that Wireshark provides. Any unusual devices around? &lt;/span&gt;  &lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;Some of our office printers have embedded OSes in them and can tell you they've never been updated by the vendor. What outdated OS is hanging around on those boxes? We're tapping into the nets now and doing some OS fingerprinting to see what we're up against - I suggest you do the same!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Laura&lt;/span&gt; &lt;span style="font-family:arial;"&gt;&lt;br /&gt;Have fun one bit at a time... &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-3214610984454735223?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/XC2CQ074hRo" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3214610984454735223?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3214610984454735223?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/XC2CQ074hRo/out-of-sight-out-of-mind.html" title="Out of Sight, Out of Mind?" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_v5vcOkUEGvc/SnoIJx2L-mI/AAAAAAAAAHY/iIKfHSYCyZI/s72-c/sonosite+m-turbo+ultrasound+copy.png" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/08/out-of-sight-out-of-mind.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QCRHw6fSp7ImA9WxJbFEQ.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-3649721193096631542</id><published>2009-07-24T21:08:00.000-07:00</published><updated>2009-07-24T22:22:45.215-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-24T22:22:45.215-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="multicast" /><category scheme="http://www.blogger.com/atom/ns#" term="qos" /><category scheme="http://www.blogger.com/atom/ns#" term="ekg pattern" /><category scheme="http://www.blogger.com/atom/ns#" term="slow network" /><title>One Key Sign of QoS Problems</title><content type="html">&lt;a style="font-family: arial;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_v5vcOkUEGvc/SmqJ4-tjgJI/AAAAAAAAAHA/HNlZotJfKEg/s1600-h/qos.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 77px;" src="http://3.bp.blogspot.com/_v5vcOkUEGvc/SmqJ4-tjgJI/AAAAAAAAAHA/HNlZotJfKEg/s200/qos.jpg" alt="" id="BLOGGER_PHOTO_ID_5362249918337745042" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;There are some trace files that &lt;span style="color: rgb(102, 0, 0); font-style: italic; font-weight: bold;font-size:130%;" &gt;&lt;span style="font-family:lucida grande;"&gt;SCREAM&lt;/span&gt;&lt;/span&gt; at you!  If you stand too closely you can feel spit hitting your face!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;In the "Top 10 Reasons Your Network is Slow" online course (&lt;/span&gt;&lt;a style="font-family: arial;" href="http://www.chappellseminars.com/s-top10.html"&gt;course abstract&lt;/a&gt;&lt;span style="font-family:arial;"&gt;), we examine one of the causes of slow network performance. We look at a trace file of traffic that has passed through a router set up with QoS. You may not be aware how obvious QoS issues can be when analyzing traffic - feed a nice steady stream through that puppy and catch the traffic on the other side to see how it performed its duties. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:arial;" &gt;Look for an EKG Pattern&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;In a datastream that is 'steady' - as in the video streaming example shown in the picture,  we look for an "EKG pattern" in data coming through the router. This pattern is seen when data is held in the queue temporarily and then released (causing the sudden jump in the IO). As you can see in the image above, we can also spot packets that are droped by the queue. (Make sure you take a trace on the other side of the router to compare the IO graphs - you want to be certain a steady stream of data is traveling towards the QoS device and any alteration in the IO pattern has not already occurred.)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:arial;" &gt;Get the Trace File&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Go ahead - try checking it out yourself. Open up &lt;/span&gt;&lt;a style="font-family: arial;" href="http://www.chappellseminars.com/traces/mcaststream-queued2.pcap"&gt;mcaststream-queued2.pcap&lt;/a&gt;&lt;span style="font-family:arial;"&gt; in Wireshark. Select Statistics &gt; IO Graph. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;What? It's not screaming at you? Aha! That is because the X axis is too large - you are looking at ants from space! Change the X axis value to 0.01 seconds. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 0, 0);font-family:arial;" &gt;SCREAM!!!! &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Do you see it? Right around 1.10 seconds into the trace - the EKG pattern! If users are not complaining about performance then dont' sweat it. Keep an eye on times when the line drops and doesn't jump up above the average point - those are dropped packets. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;I'll be teaching the "Top 10 Reasons Your Network is Slow" on July 30th - it's a fun class to teach (although last time I was demonstrating the process of jamming a wireless network and nearly killed my own seminar hosting connection - duh). &lt;/span&gt;&lt;span style="font-family: arial;"&gt;Register &lt;a href="http://www.chappellseminars.com/s-top10.html"&gt;here&lt;/a&gt;. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:arial;" &gt;Enjoy the trace! See you online!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Laura&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-3649721193096631542?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/nVz7M4b87VE" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3649721193096631542?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3649721193096631542?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/nVz7M4b87VE/one-key-sign-of-qos-problems.html" title="One Key Sign of QoS Problems" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_v5vcOkUEGvc/SmqJ4-tjgJI/AAAAAAAAAHA/HNlZotJfKEg/s72-c/qos.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/07/one-key-sign-of-qos-problems.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUAHQH05fip7ImA9WxJUGUk.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-1644218372026790481</id><published>2009-07-18T09:48:00.000-07:00</published><updated>2009-07-18T12:02:11.326-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-18T12:02:11.326-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bl-ear project" /><category scheme="http://www.blogger.com/atom/ns#" term="bluetooth" /><category scheme="http://www.blogger.com/atom/ns#" term="wired magazine" /><category scheme="http://www.blogger.com/atom/ns#" term="brad pitt" /><title>Brad and the Top-Secret Bl-Ear Project</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_v5vcOkUEGvc/SmIBrcATeoI/AAAAAAAAAGw/fPULz39KXoY/s1600-h/blear.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 168px;" src="http://1.bp.blogspot.com/_v5vcOkUEGvc/SmIBrcATeoI/AAAAAAAAAGw/fPULz39KXoY/s200/blear.png" alt="" id="BLOGGER_PHOTO_ID_5359848352287783554" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: arial;"&gt;Brad Pitt on the cover of wired poo-pooing the bluetooth look? No way! They aren't going pre-announce an invention that I already pre-announced at TechEd?! I quickly blew through the pages of Wired Magazine's August issue to find a picture of Brad texting at the urinals with a bourbon close by (page 89).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Whew! No mention of the Bl-Ear - the exciting beta-phase invention in bluetooth beauty and buffness. It's tough to stay ahead of the game (and game mags) in technology. Sometimes you have to be... well... inventive.&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Let's face it - there are tons of products we'd love to see out there - the Bl-Ear fills a need to reduce the high Nerdlook-Factor (NF) of walking around with that bluetooth device hanging off your head - don't even start spewing the "jawbone is sexy" defense with me. No one (not even Brad) looks good with electronics hanging off their aural lobes.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 0, 0); font-weight: bold; font-style: italic;"&gt;Bluetooth devices are the new pocket-protectors, folks. And you need to admit it. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;As you may have missed the TechEd presentation in May, I've put up a short video showing the Bl-ear over at the &lt;a href="http://www.chappellseminars.com/projects.html"&gt;Chappell Seminars Projects page&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Before you go out the door today, look in the mirror. Laptop - check. iPhone - check. Starbucks card - check. Bluetooth adapter - check. Now remember - accessorize, then minimize - take off the ear-tech that screams "I hope someone wants to talk to me today".&lt;br /&gt;&lt;br /&gt;Sign up for the Bl-Ear and watch your NF drop to near-normal levels. Oh... and just wait 'til you see their upcoming Ear-Bluds! I can hardly wait.&lt;br /&gt;&lt;br /&gt;Laura &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family: arial;"&gt;The Bl-ear and Blear Corporation are bunk. All rights reserved.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-1644218372026790481?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/GHahtaBOAtg" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/1644218372026790481?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/1644218372026790481?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/GHahtaBOAtg/brad-and-top-secret-bl-ear-project.html" title="Brad and the Top-Secret Bl-Ear Project" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_v5vcOkUEGvc/SmIBrcATeoI/AAAAAAAAAGw/fPULz39KXoY/s72-c/blear.png" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/07/brad-and-top-secret-bl-ear-project.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkAARH0yfyp7ImA9WxJUFEk.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-6892401973790602465</id><published>2009-07-12T16:02:00.000-07:00</published><updated>2009-07-12T17:25:45.397-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-12T17:25:45.397-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="troubleshooting" /><category scheme="http://www.blogger.com/atom/ns#" term="dad" /><category scheme="http://www.blogger.com/atom/ns#" term="printing" /><title>Parents, 'Puters and Painkillers</title><content type="html">&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_v5vcOkUEGvc/Slp1HJAm-II/AAAAAAAAAGo/X3tmNEGiuYQ/s1600-h/confusedsign-small.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 161px;" src="http://3.bp.blogspot.com/_v5vcOkUEGvc/Slp1HJAm-II/AAAAAAAAAGo/X3tmNEGiuYQ/s200/confusedsign-small.jpg" alt="" id="BLOGGER_PHOTO_ID_5357723472248633474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);font-family:arial;" &gt;"Hi hon! How are you? How are the kids? I can't print"...&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;Being a technologist these days is like being the family doctor in the olden days (ok, well, family doctors are still of value but mostly for prescription drugs for fun I think.) &lt;/span&gt;  &lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;You know what it's like - your second cousin once removed calls - you haven't seen her since that embarrassing Thanksgiving when they pulled you into singing "Muscrat Love" with them while your inebriated Aunt tried to play the piano &lt;span style="color: rgb(102, 102, 102); font-style: italic;"&gt;("I haven't played since I was a child" - no kidding?!)&lt;/span&gt;. [That's another story.]. &lt;span style="color: rgb(102, 102, 102); font-style: italic;"&gt;"Hey... are you still into computers?"&lt;/span&gt;  &lt;/span&gt;&lt;span style="font-family:arial;"&gt;Uh... no. I'm now working at a humane beef ranch as an ozone protection analyst. Sorry.&lt;br /&gt;&lt;br /&gt;In this case, my father was calling for help with printing. &lt;/span&gt;  &lt;span style="font-family:arial;"&gt;Guiding him to view the print queue won't work - the print queue icon seems invisible to him and the Start button is out of the question &lt;span style="color: rgb(102, 102, 102); font-style: italic;"&gt;("The start button... you mean the power button? Ok. I clicked it, but my computer screen is blank now.")&lt;/span&gt;. &lt;/span&gt;  &lt;span style="font-family:arial;"&gt;First things first. Do you see a light on in the front of the printer &lt;span style="color: rgb(102, 102, 102); font-style: italic;"&gt;("Yes, honey. My desk lamp is always on.")&lt;/span&gt;? &lt;/span&gt;  &lt;span style="font-family:arial;"&gt;It would be a long, slow and painful process (looking for the real family doctor for those fun meds now) to guide my father to eventually unplug and replug in the printer USB cable on his laptop &lt;span style="color: rgb(102, 102, 102); font-style: italic;"&gt;("no, Dad... the printer cable doesn't plug into the wall socket...get out from under the table before you hurt yourself.")&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;The printer sprung to life and began printing the &lt;span style="font-weight: bold;"&gt;32 copies&lt;/span&gt; of the 70-page document he'd sent to it before calling me. Rather than try to guide him through the process of clearing the print queue I just told him that there wasn't anything he could do about it. &lt;span style="color: rgb(153, 153, 153); font-style: italic;"&gt;"Just get out the recycling bin, Dad."&lt;/span&gt; (Making notes to give Dad reams of paper next birthday and go out to plant something green while acknowledging the guilt of prioritizing my sanity over the environment).&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;You must have a certain level of compassion and empathy to work in the field of technical support. I really don't know how people take calls from someone like my father every day and still maintain a life of sobriety and love towards mankind. I think the key must be...&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;Hang on... gotta cut this blog short... my Dad's calling... &lt;span style="color: rgb(102, 102, 102); font-style: italic;"&gt;("Honey... I've just downloaded Wireshark and I have a couple questions...")&lt;/span&gt;&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;Gulp.&lt;br /&gt;&lt;br /&gt;Laura&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(192, 192, 192);"&gt;Family... can't live with 'em... can't DoS 'em (legally)&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-6892401973790602465?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/OsxU2CFZikU" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/6892401973790602465?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/6892401973790602465?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/OsxU2CFZikU/parents-puters-and-painkillers.html" title="Parents, 'Puters and Painkillers" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_v5vcOkUEGvc/Slp1HJAm-II/AAAAAAAAAGo/X3tmNEGiuYQ/s72-c/confusedsign-small.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/07/parents-puters-and-painkillers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkUHQnc-cSp7ImA9WxJVGE4.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-4933806044111966550</id><published>2009-07-05T15:31:00.000-07:00</published><updated>2009-07-05T16:57:13.959-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-05T16:57:13.959-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="comcast" /><category scheme="http://www.blogger.com/atom/ns#" term="training" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><title>Did That Tech Just Tell Me to Go Ping Myself?</title><content type="html">&lt;a href="http://4.bp.blogspot.com/_v5vcOkUEGvc/SlE2KLBcToI/AAAAAAAAAGY/3EIRzK_I9GM/s1600-h/nerdhead.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 171px; FLOAT: left; HEIGHT: 137px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5355120980305661570" border="0" alt="" src="http://4.bp.blogspot.com/_v5vcOkUEGvc/SlE2KLBcToI/AAAAAAAAAGY/3EIRzK_I9GM/s200/nerdhead.jpg" /&gt;&lt;/a&gt; &lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;em&gt;"Ping 127.0.0.1 and let's look for packet loss."&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;em&gt;"Let's reinstall the operating system."&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;em&gt;"Oh my gawd - didn't you know ping is illegal?"&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;em&gt;"Ping takes away the addresses of others on the network."&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;em&gt;"Not all laptops support networking, so that might be the problem."&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;em&gt;"Did you plug in the wireless cable yet?"&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;Oh yes... I keep track of the amazing comments I've heard from hotel network technicians and most recently Comcast. Many of you know the story of "Bob, the Comcast technician from hell" who ended up being &lt;gasp!&gt;a trainer for the other network technicans. I can only hope Bob is now flipping burgers somewhere.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;When one of my network connections began feeling last week I pulled out my tools and began to work on identifying where the problem was. I grabbed my traffic with Wireshark and noted the high rate of packet loss. Since I know that packet loss most often occurs at an inter-network device, I began running the graphical ping in NetScanTools. I could see the rate of packet loss was around 40%. Next I began a series of traceroute operations to see where I was losing packets - and BOOM! There it was. One of the routers consistently dropped packets along the path. I even went through that target to other hosts. &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;All I needed to do was let the Comcast technician know which router was the problem... right? &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;When the Comcast technician asked me to "ping 127.0.0.1", I tried not to gag. How could this 'technician' not know the basics of TCP/IP? She pronounced traceroute as "trace-ert" with absolutely no awareness that her ignorance was spilling out over the phone. &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;What I experienced here is the result of skipping basic training - it's really not her fault. I blame Comcast. And guess what...? Right now we are seeing companies restrict training budgets for the folks running their networks. We're going to pay a big price in the future with unskilled and out-of-date IT professionals. &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;Is your company restricting training? What are you doing to keep up? Does your management know the end result of de-valuing training? Where will we be in a few months... years?&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;I hope the free Wireshark training courses are helping out. We are focusing on getting sponsors to open up more free online training. Let your favorite vendors know they can do something great for the industry by sponsoring a free training course. &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;Now off to finish the Wireshark 101 handouts for class on Tuesday! Gerald (the creator of Wireshark) will be online again to answer your questions. I hope to see you there! Register at &lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://www.chappellseminars.com/"&gt;http://www.chappellseminars.com&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; today. &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;Laura&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-4933806044111966550?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/p1JLiXI3r0s" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/4933806044111966550?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/4933806044111966550?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/p1JLiXI3r0s/did-that-tech-just-tell-me-to-go-ping.html" title="Did That Tech Just Tell Me to Go Ping Myself?" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_v5vcOkUEGvc/SlE2KLBcToI/AAAAAAAAAGY/3EIRzK_I9GM/s72-c/nerdhead.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/07/did-that-tech-just-tell-me-to-go-ping.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0ICRXY6fSp7ImA9WxJVGEg.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-3771335996169211457</id><published>2009-07-04T22:44:00.000-07:00</published><updated>2009-07-05T22:52:44.815-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-05T22:52:44.815-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="chappell university" /><category scheme="http://www.blogger.com/atom/ns#" term="training" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><title>July 7th - Wireshark Jumpstart Free (Sponsored by NetOptics)</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_v5vcOkUEGvc/SlGPcbhyksI/AAAAAAAAAGg/8PK0vb1Kr5o/s1600-h/NetOptics.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 75px; height: 26px;" src="http://3.bp.blogspot.com/_v5vcOkUEGvc/SlGPcbhyksI/AAAAAAAAAGg/8PK0vb1Kr5o/s200/NetOptics.jpg" alt="" id="BLOGGER_PHOTO_ID_5355219150508823234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;The July 7th Wireshark 101 Jumpstart is sponsored by NetOptics. I approached NetOptics because my lab is filled with NetOptics taps... the Teeny Tap, my 10/100 aggregating tap, my 10/100/1000 regenerating tap and more. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;In this Wireshark 101 Jumpstart, I'll be demonstrating the following features of Wireshark:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Tapping into traffic&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Choosing the interface&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Capture filtering&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Display filtering&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Capturing to file sets&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Capturing with a ring buffer&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Altering the time column&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Display filtering&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Using the Expert Info Composite&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Defining profiles&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Reassembling streams&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: arial;"&gt;We already have over 1,000 registrations and only 1,000 people will be allowed to access the live online seminar. We'll open up the 'waiting room' online approximately 20 minutes before the session to allow you to get a place in the course. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;See you on Tuesday, July 7th. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Laura&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-3771335996169211457?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/PYkcU8ufU6A" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3771335996169211457?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3771335996169211457?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/PYkcU8ufU6A/july-7th-wireshark-jumpstart-free.html" title="July 7th - Wireshark Jumpstart Free (Sponsored by NetOptics)" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_v5vcOkUEGvc/SlGPcbhyksI/AAAAAAAAAGg/8PK0vb1Kr5o/s72-c/NetOptics.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/07/july-7th-wireshark-jumpstart-free.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0QBRXYyeCp7ImA9WxJVEU4.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-449922701415972617</id><published>2009-06-27T10:00:00.000-07:00</published><updated>2009-06-27T12:35:54.890-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-27T12:35:54.890-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="podcasting" /><category scheme="http://www.blogger.com/atom/ns#" term="twitter" /><category scheme="http://www.blogger.com/atom/ns#" term="tweetdeck" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><category scheme="http://www.blogger.com/atom/ns#" term="channelweb" /><title>Laughing at Twitter Traffic!</title><content type="html">&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_v5vcOkUEGvc/SkW02rckGrI/AAAAAAAAAGQ/1w3STKNmhgw/s1600-h/icon_c.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 128px; height: 128px;" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/SkW02rckGrI/AAAAAAAAAGQ/1w3STKNmhgw/s200/icon_c.png" alt="" id="BLOGGER_PHOTO_ID_5351882583668169394" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;It's true... I was laughing out loud today... at packets! &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;This project came out of thin air almost... I was preparing for a podcast with the ChannelWeb group (you can listen to it at http://community.crn.com/docs/DOC-1082). I was on the phone line early with the moderator and interviewers and making small talk. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;I mentioned that I'd tried to do some Tweeting that morning and there were problems. I explained how I used Wireshark to determine the problem had nothing to do with my system. There seemed to be a problem with the twitter.com website. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;When the interview started, Ed Moltzen (a very impressive Tweeter and interviewer) led the discussion back to my early morning problems with twitter.com. As I talked about the problem, it suddenly occurred to me that people might like to know what Tweet traffic looks like. I told Ed that I'd do an analysis of a Tweet after the podcast. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;I did... I immediately got working on a clean trace showing just the Tweet. That was no easy feat since my host spewed all sorts of background traffic for unrelated processes. I began identifying and whittling away traffic that was unrelated. Finally - I sent my sample Tweet and created my analysis report. But I wasn't done... &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;TweetDeck was ripe for an analysis... and here's when life got really fun. It turns out that when you upload your Twitter picture it is placed on an Amazon Web Server (AWS) under the original file name. Each user has a unique user ID and the image is placed in that directory under a directory called profile_images. &lt;/span&gt;&lt;span style="font-family:arial;"&gt;The picture names were hysterical!&lt;/span&gt; &lt;ul style="font-family: arial;"&gt;&lt;li&gt;WhatSheWants&lt;/li&gt;&lt;li&gt;MeNoWife&lt;/li&gt;&lt;li&gt;Spoon_too_big&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family:arial;"&gt;You can read the entire report at www.chappellseminars.com/projects.html. I also released the MAC World Domination project details at that location. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Register for the newsletter over at www.chappellseminars.com/newsletter.html to keep up with the latest projects in my lab. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;Now - off I go... the packets are calling!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;Laura&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-449922701415972617?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/TSNjRV9vDok" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://laurachappell.blogspot.com/feeds/449922701415972617/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7740546072062781853&amp;postID=449922701415972617" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/449922701415972617?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/449922701415972617?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/TSNjRV9vDok/laughing-at-twitter-traffic.html" title="Laughing at Twitter Traffic!" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_v5vcOkUEGvc/SkW02rckGrI/AAAAAAAAAGQ/1w3STKNmhgw/s72-c/icon_c.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://laurachappell.blogspot.com/2009/06/laughing-at-twitter-traffic.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QNQ3oyeyp7ImA9WxJWFkU.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-5145574543595625650</id><published>2009-06-21T14:00:00.000-07:00</published><updated>2009-06-22T09:49:52.493-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-22T09:49:52.493-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="sharkfest" /><category scheme="http://www.blogger.com/atom/ns#" term="mDNS" /><category scheme="http://www.blogger.com/atom/ns#" term="iPhone" /><category scheme="http://www.blogger.com/atom/ns#" term="AirPcap" /><title>iPhone: You're Sexy, but You Talk Too Much</title><content type="html">&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_v5vcOkUEGvc/Sj6-YCib2NI/AAAAAAAAAGI/Ok75phWFPoQ/s1600-h/iphonesexy.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 145px; height: 200px;" src="http://4.bp.blogspot.com/_v5vcOkUEGvc/Sj6-YCib2NI/AAAAAAAAAGI/Ok75phWFPoQ/s200/iphonesexy.jpg" alt="" id="BLOGGER_PHOTO_ID_5349922727570168018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Last week at Sharkfest I blabbered on a bit about the chatty nature of my iPhone (3G). I equated it to a yapping Chihuahua on the network. I'm still playing around a bit with numerous trace files and will have some to give away soon, but I wanted to explain how to capture your iPhone traffic and understand one of the packets that you'll see over and over and over and (you get it) again in your traffic.&lt;br /&gt;&lt;br /&gt;I'm hanging out today on my Vista 64 system that I host the live seminars from. (No... I do not have a sexy MAC on my desk - but I do have two televisions within 10 feet of me to constantly feed me my much-needed background noise through the day.)&lt;br /&gt;&lt;br /&gt;Before launching Wireshark or turning on my iPhone - here's what I did:&lt;br /&gt;&lt;br /&gt;1. I hooked up a powered USB hub and populated it with three AirPcap adapters.&lt;br /&gt;2. I opened the AirPcap control panel and configured each adapter to listen to a different channel - channels 1, 6 and 11.&lt;br /&gt;3. I added my encryption keys in AirPcap.&lt;br /&gt;&lt;br /&gt;Now I launched Wireshark and selected the AirPcap Multi-Channel Aggregator interface for my capture. Then I turned on my sweet, sexy-looking iPhone and...&lt;br /&gt;&lt;br /&gt;OUCH! I watched my iPhone locate the WLAN APs, but it did not make an authentication/association until 60 seconds after I entered my passcode. Perhaps it wanted a bit more of a commitment from me? Or flowers? Or a new case?&lt;br /&gt;&lt;br /&gt;During the startup sequence there were some unique DHCP and ARP happenings (we'll cover in a later blog) and a slew of mDNS packets. So, you ask... what the heck is mDNS and do I want 'em on my WLAN? mDNS stands for multicast DNS and is used to discover local devices as part of the zeroconfig project definition (Apple calls it Bonjour - they are so cool!). You don't need a DNS server to discover mDNS-capable devices. mDNS runs over UDP port 5353. Just use a &lt;span style="font-family:courier new;"&gt;udp.port==5353&lt;/span&gt; filter or the &lt;span style="font-family:courier new;"&gt;dns&lt;/span&gt; display filter in Wireshark to see all mDNS and DNS traffic or build a filter for all &lt;span style="font-family:courier new;"&gt;ip.addr==224.0.0.251&lt;/span&gt; traffic (the IPv4 mDNS multicast address) or &lt;span style="font-family:courier new;"&gt;ipv6.addr==FF02::FB&lt;/span&gt;, in the case of IPv6.&lt;br /&gt;&lt;br /&gt;Want to try it out? On your iPhone, search in the AppStore for &lt;a href="http://www.feass.net/software/iphone/index.html"&gt;mDNS Watch&lt;/a&gt;. It's free so install it and watch it list all the mDNS-capable devices around you. In my lab it discovered my HP Officejet Pro L7700 printer and it showed me the three ports that were open on that printer - ports 513, 80 and 9100. Hmmm... this could be interesting, couldn't it?&lt;br /&gt;&lt;br /&gt;For more information on mDNS, visit &lt;a href="http://files.multicastdns.org/draft-cheshire-dnsext-multicastdns.txt"&gt;http://files.multicastdns.org/draft-cheshire-dnsext-multicastdns.txt&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Now... back to that hot, sexy and really verbose iPhone to work on the strange DHCP and ARP behavior (much of which is related to Bonjour).&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-5145574543595625650?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/cYv2TiVxC60" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/5145574543595625650?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/5145574543595625650?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/cYv2TiVxC60/iphone-youre-sexy-but-you-talk-too-much.html" title="iPhone: You're Sexy, but You Talk Too Much" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_v5vcOkUEGvc/Sj6-YCib2NI/AAAAAAAAAGI/Ok75phWFPoQ/s72-c/iphonesexy.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/06/iphone-youre-sexy-but-you-talk-too-much.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkANQH85eip7ImA9WxJWEEg.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-1258022400287395646</id><published>2009-06-12T23:29:00.000-07:00</published><updated>2009-06-15T02:39:51.122-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-15T02:39:51.122-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Gerald Combs" /><category scheme="http://www.blogger.com/atom/ns#" term="pcap-ng" /><category scheme="http://www.blogger.com/atom/ns#" term="update" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><title>Wireshark v1.2 Enhancements</title><content type="html">&lt;div&gt;&lt;a style="" href="http://2.bp.blogspot.com/_v5vcOkUEGvc/SjNT5mcilTI/AAAAAAAAAGA/YvIJ_-InZ9M/s1600-h/latestnews2.jpg"&gt;&lt;img style="margin: 0px 10px 10px 0px; width: 200px; float: left; height: 150px;" id="BLOGGER_PHOTO_ID_5346709431656813874" alt="" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/SjNT5mcilTI/AAAAAAAAAGA/YvIJ_-InZ9M/s200/latestnews2.jpg" border="0" /&gt;&lt;/a&gt; &lt;span style="font-family:arial;"&gt;In this week's newsletter I got carried away with details about the next version of Wireshark - it almost became a book. This blog details some of the enhancements in &lt;a href="http://www.wireshark.org/"&gt;Wireshark v1.2&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;One of the hot features that many will be thrilled about is auto-completion of display filters! HALLELUJAH! Bad typicsts rejoice (I meant to make that mistake...). Type in "i" and possible filters are shown in a drop-down list. Add a "p" and a period ("ip.") and all the possible variations of filters starting with "ip." show up. This is going to save us all a lot of time!&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;I already talked a bit about the GeoIP stuff in the Newletter and I'll be blogging/teaching about this a bit in the coming weeks. &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;There are a few changes that might sneak up on you - for example, in the Expert Info Composite area, "Window is Zero" and "Window Full" have moved to Warnings, but "Retransmissions" was not moved over - "Fast Retransmissions" are already in the Warnings area. It would be nice to have both types of retransmissions in the same window. We do now have the individual item count as well as the summary count in &lt;/span&gt;&lt;span style="font-family:arial;"&gt;the tabs now, which is really nice. &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;There were some usability enhancements as well. For example, Wireshark v1.2 now remembers you column widths and opens up with the last configuration profile you used (watch out for this one if you're accustomed to always starting with the default profile and having to switch over).&lt;/span&gt; &lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;As far as bug fixes go, the NetFlow dissector bug that could "run off with your dog, crash your truck, and write a country music song about the experience" has been fixed. No kidding - that is in the 1.2 rc1 release notes from Gerald. &lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;Something that you may not take advantage of quite yet (but we'll cover in future newletters and online training over at chappellseminars.com is the new support for &lt;a href="http://wiki.wireshark.org/Development/PcapNg"&gt;pcap-ng&lt;/a&gt;, the next-generation capture file format. These trace files typically end in the extension .ntar, but the recommended extension is .pcapng. This new trace file will enable us to add metadata to our trace files. &lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;Again... the developers did a great job with this version - kudos to them all!&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;I'll be moving over to the new version of Wireshark for all the chappellseminars.com courses as soon as the "official" release is completed. &lt;a href="http://www.chappellseminars.com/courses.html"&gt;Register&lt;/a&gt; for a course today! &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;Note&lt;/strong&gt;: [25% Discount Code: bcbsab - use for the new &lt;a href="http://www.chappellseminars.com/t-commandlines.html"&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;Wireshark Command-Line Tools: From Editcap to Tshark&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; - July 13, 2009 @ 10:00AM PDT/GMT-7 &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Survey: Chappell Seminars "&lt;a href="http://www.surveymonkey.com/s.aspx?sm=X6Xpg21jrvyTVW68TYjeRw_3d_3d"&gt;Take the Reigns&lt;/a&gt;"&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Twitter: &lt;a href="http://www.twitter.com/laurachappell"&gt;LauraChappell&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Facebook: &lt;a href="http://www.facebook.com/laurachappell"&gt;Laura Chappell&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-1258022400287395646?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/z5yrSonEXzU" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/1258022400287395646?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/1258022400287395646?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/z5yrSonEXzU/wireshark-v12-enhancements.html" title="Wireshark v1.2 Enhancements" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_v5vcOkUEGvc/SjNT5mcilTI/AAAAAAAAAGA/YvIJ_-InZ9M/s72-c/latestnews2.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/06/wireshark-v12-enhancements.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcBRnw7eSp7ImA9WxJQGU0.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-1050011308080312746</id><published>2009-06-01T15:08:00.000-07:00</published><updated>2009-06-01T18:27:37.201-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-01T18:27:37.201-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="NetScanTools" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><category scheme="http://www.blogger.com/atom/ns#" term="Online Seminars" /><title>You Can't Hide!</title><content type="html">&lt;a href="http://1.bp.blogspot.com/_v5vcOkUEGvc/SiR_1SlBs5I/AAAAAAAAAFw/GGKf891a6y4/s1600-h/tracert-ms.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 188px; FLOAT: left; HEIGHT: 200px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5342535611465184146" border="0" alt="" src="http://1.bp.blogspot.com/_v5vcOkUEGvc/SiR_1SlBs5I/AAAAAAAAAFw/GGKf891a6y4/s200/tracert-ms.jpg" /&gt;&lt;/a&gt; &lt;div&gt;&lt;span style="font-family:arial;"&gt;You may be familiar with the standard old traceroute that relies on ICMP echo request and echo reply packets to identify the path to a target and verify the target reachability. If so... how many times have you not reached the target because they filter ICMP echo replies?&lt;br /&gt;&lt;br /&gt;An example of this would be when you try to traceroute to &lt;/span&gt;&lt;a href="http://www.microsoft.com/"&gt;&lt;span style="font-family:arial;"&gt;http://www.microsoft.com/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;. You'll see right after you hit the msn.net domain routers you are left in the dust. It really isn't that unusual to block ICMP echo requests at servers - no one should be pinging them anyway, right?&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;Using TCP Traceroute&lt;/strong&gt;&lt;br /&gt;Using NetScanTools Pro, I typically use TCP traceroutes. In the Traceroute tool, click the Setup button and choose TCP (WinPcap). You can define the starting hop, timeout in miliseconds, and retries at this point, but I go directly down to the TCP Trace Specific area. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;Here's how the TCP Traceroute works - NetScanTools sends out a series of TCP SYN (handshake) packets to the target. It increments the Time-to-Live (TTL) value in the IP header (just as an ICMP traceroute does) to locate routers along the path who respond with ICMP Time to Live Exceeded in Transit messages. When the hop count is high enough to allow the TCP SYN to make it to the target, that target MUST respond - hey those are the rules of TCP. The target must respond with either a TCP SYN/ACK (indicating the target port is open) or a RST (reset, indicating the target port is closed). In this case, we don't really care if the target port is open or closed - we're just trying to get the roundtrip time using traceroute. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;strong&gt;Firewalled/Blocked Targets&lt;/strong&gt;&lt;br /&gt;Now we know the specs for TCP say the target must respond... but what if it doesn't? What could have happened. Well... either your TCP SYN packet never made it there or the TCP SYN/ACK or RST never made it back. Make sure you run your TCP traceroute a few times to ensure sporadic packet loss isn't to blame. Most likely it is likely a firewall or some other blocking device that in your way. You couldn't find the roundtrip time, but you did find a protected host.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;FYI - NetScanTools Pro 2-for-1 Price&lt;/strong&gt;&lt;br /&gt;As you may know, NetScanTools is on my 'must have' list of tools for IT professionals. The new version (updated today) is available at &lt;/span&gt;&lt;a href="http://www.netscantools.com/"&gt;&lt;span style="font-family:arial;"&gt;www.netscantools.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;. There is also a 2-for-1 sale online through June 15, 2009.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Learn More&lt;br /&gt;&lt;/strong&gt;In the upcoming "Trace Back to a Suspect Host" course (June 4) I'll demonstrate each form of traceroute along with numerous other invasive/non-invasive techniques for testing connectivity, paths, identities and relationships of targets. Register online at &lt;/span&gt;&lt;a href="http://www.chappellseminars.com/sem-traceback.html"&gt;&lt;span style="font-family:arial;"&gt;www.chappellseminars.com/sem-traceback.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;. &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;color:#990000;"&gt;&lt;em&gt;Laura&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-1050011308080312746?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/z-No2qSLsXs" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/1050011308080312746?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/1050011308080312746?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/z-No2qSLsXs/you-cant-hide.html" title="You Can't Hide!" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_v5vcOkUEGvc/SiR_1SlBs5I/AAAAAAAAAFw/GGKf891a6y4/s72-c/tracert-ms.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/06/you-cant-hide.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkIHSXw5eCp7ImA9WxJQEUU.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-5580069222716336215</id><published>2009-05-24T09:42:00.000-07:00</published><updated>2009-05-24T10:02:18.220-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-24T10:02:18.220-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="video" /><category scheme="http://www.blogger.com/atom/ns#" term="twitter" /><category scheme="http://www.blogger.com/atom/ns#" term="application analysis" /><category scheme="http://www.blogger.com/atom/ns#" term="IO graph" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><title>Analyzing Video Spews</title><content type="html">&lt;a href="http://1.bp.blogspot.com/_v5vcOkUEGvc/Shl5GaXsIEI/AAAAAAAAAFI/UecwdcmheUo/s1600-h/io-webcasting.png"&gt;&lt;span style="font-family:arial;font-size:78%;"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 200px; FLOAT: left; HEIGHT: 110px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5339431984289292354" border="0" alt="" src="http://1.bp.blogspot.com/_v5vcOkUEGvc/Shl5GaXsIEI/AAAAAAAAAFI/UecwdcmheUo/s200/io-webcasting.png" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:78%;"&gt; [Follow me at &lt;/span&gt;&lt;a href="http://www.twitter.com/laurachappell"&gt;&lt;span style="font-family:arial;font-size:78%;"&gt;www.twitter.com/laurachappell&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:78%;"&gt;]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;Have you analyzed your application traffic today?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;As we prepare for the online seminar this week (see &lt;a href="http://tinyurl.com/pputte"&gt;http://tinyurl.com/pputte&lt;/a&gt;), I played around a bit with adding video feeds to the training. GoToWebinar (our hosting solution at this time) does not support video feeds as iLinc and others do, but we found a workaround by having the LifeCam video window up in the background and showing th entire desktop. &lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="font-size:78%;"&gt;[Personally I am not to keen on feeding video... there are many eves when I work until 3am, get up with the kids at 6am and the thought of putting on being seen in my comfy "Big Dogs" sweatshirt makes me cringe. I can't wait until virtual avatars can be synced with a voice!]&lt;/span&gt;&lt;/p&gt;To set up this analysis I simply created a new online seminar, joined as a speaker on one computer and joined as an attendee on a second computer. I launched Wireshark on my speaker computer and started up the seminar. I joined the seminar as an attendee on the second computer.&lt;br /&gt;&lt;br /&gt;Here's what I found about the datastream -&lt;br /&gt;&lt;br /&gt; - When just showing the entrance slide the traffic rate averaged less than 500,000 bits/second.&lt;br /&gt; - When I moved through a slide deck or showed Wiershark screens, the IO jumped infrequencly up to 2,000,000 bits/second.&lt;br /&gt; - When I launched the video and showed no movement (camera pointed at the wall), the stream reached an almost steady 2,500,000 bits/second. Showing my kids jumping on the trampoline had no effect on the video stream rate - it's always sending out the current image regardless of the level of change to the video image.&lt;br /&gt;&lt;br /&gt;I tweeted the full-size image of this over at &lt;a href="http://www.twitter.com/laurachappell"&gt;www.twitter.com/laurachappell&lt;/a&gt; - you can look at it at &lt;a href="http://twitpic.com/5ust4"&gt;http://twitpic.com/5ust4&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Next I'll look at iLinc's traffic with and without video enabled...&lt;br /&gt;&lt;br /&gt;Laura&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-5580069222716336215?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/39E3rCN7LaU" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/5580069222716336215?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/5580069222716336215?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/39E3rCN7LaU/analyzing-video-spews.html" title="Analyzing Video Spews" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_v5vcOkUEGvc/Shl5GaXsIEI/AAAAAAAAAFI/UecwdcmheUo/s72-c/io-webcasting.png" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/05/analyzing-video-spews.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUQAQns7eip7ImA9WxJQEUU.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-4720848698603235895</id><published>2009-05-21T11:23:00.000-07:00</published><updated>2009-05-24T09:42:23.502-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-24T09:42:23.502-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="humor" /><category scheme="http://www.blogger.com/atom/ns#" term="twitter" /><category scheme="http://www.blogger.com/atom/ns#" term="microsoft" /><category scheme="http://www.blogger.com/atom/ns#" term="apple" /><title>Potential Lives Where...?</title><content type="html">&lt;a href="http://2.bp.blogspot.com/_v5vcOkUEGvc/ShWct8XLfkI/AAAAAAAAAFA/KCe0KlAl5IA/s1600-h/potential.jpg"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 200px; FLOAT: left; HEIGHT: 150px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5338345246428986946" border="0" alt="" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/ShWct8XLfkI/AAAAAAAAAFA/KCe0KlAl5IA/s200/potential.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="font-size:78%;"&gt;[Follow me at &lt;/span&gt;&lt;/strong&gt;&lt;a href="http://www.twitter.com/laurachappell"&gt;&lt;strong&gt;&lt;span style="font-size:78%;"&gt;www.twitter.com/laurachappell&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;span style="font-size:78%;"&gt;]&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;I captured this image at TechEd last week. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Walking into the TechEd Live taping session I noticed the video crew was a bit more high-tech than in past years - this year they would capture the video directly to disk and reduce the video-to-production time down to less than 48 hours! Nicely done!&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;When I approached the video console area, I noticed the vidiots (an endearing term for those AV geeks whom I respect tremendously now...) were running on MACs. Microsoft had likely asked them to cover the MAC logo on their computer, but failed to realize the Apple logo is backlit. This made for a very interesting image when the Microsoft slogan "Potential Lives Here ---&gt;" pointed directly to the Apple logo. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;One of the many interesting moments at TechEd North America - don't even get me started on the beach ball geekfest party!&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;Laura&lt;/p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-4720848698603235895?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/WmzZ9sv3atA" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/4720848698603235895?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/4720848698603235895?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/WmzZ9sv3atA/potential-lives-where.html" title="Potential Lives Where...?" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_v5vcOkUEGvc/ShWct8XLfkI/AAAAAAAAAFA/KCe0KlAl5IA/s72-c/potential.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/05/potential-lives-where.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMMQno9fyp7ImA9WxJRGU8.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-6284969579949518634</id><published>2009-05-21T08:56:00.000-07:00</published><updated>2009-05-21T10:54:43.467-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-21T10:54:43.467-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="twitter" /><title>Twitter Spitter</title><content type="html">&lt;a href="http://2.bp.blogspot.com/_v5vcOkUEGvc/ShWUZwpP1QI/AAAAAAAAAE4/uvCkJJgGK7k/s1600-h/bird-sideways-poop.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 142px; FLOAT: left; HEIGHT: 104px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5338336103593137410" border="0" alt="" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/ShWUZwpP1QI/AAAAAAAAAE4/uvCkJJgGK7k/s200/bird-sideways-poop.jpg" /&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;The dreaded email crossed my desk just minutes ago... &lt;/span&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;My friend Wil M. asked... "&lt;em&gt;Are you on Twitter yet? You need to be! :-)"&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Don't even try to placate me with your old-fashioned emoticon that blatantly acknowledges that I am comfy in my old habits! I know what you want me to do - spit out my life in little twit-turds? &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Who wants to read that? (Hmmm... well I am going to spend a bit of time programming my new dual-trunking scanner this morning... and then I'm analyzing the impact of adding video to an online seminar to determine minimum throughput requirements if we add video streaming to the online seminars... hmmm... that's kinda geeky, isn't it?)&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Will this be a big time-suck or a productive way to keep folks up-to-date on what's happening in the lab and upcoming events? Should I keep to techie topics or give you a glimpse into my somewhat twisted life of work, motherhood, amateur race car driver, balloon-shaper, hot tubber, sock collector, people watcher and closet nun-o-phile? &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;You tell me... should I kill the "Bluebird of Blabbering" or feed it pellets for a bit and see if the cage cleaning process is too much... (hmm... I wonder if it would be easier to cook than turkey...)&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Laura&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-6284969579949518634?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/Gnnx7szUHKY" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/6284969579949518634?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/6284969579949518634?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/Gnnx7szUHKY/twitter-spitter.html" title="Twitter Spitter" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_v5vcOkUEGvc/ShWUZwpP1QI/AAAAAAAAAE4/uvCkJJgGK7k/s72-c/bird-sideways-poop.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/05/twitter-spitter.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUERHg_eSp7ImA9WxJSEkQ.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-2421372538641654828</id><published>2009-05-02T11:42:00.000-07:00</published><updated>2009-05-02T12:40:05.641-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-02T12:40:05.641-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="implants" /><category scheme="http://www.blogger.com/atom/ns#" term="cyber-bio" /><category scheme="http://www.blogger.com/atom/ns#" term="wi-spy" /><category scheme="http://www.blogger.com/atom/ns#" term="stelaric" /><category scheme="http://www.blogger.com/atom/ns#" term="star trek" /><title>What a Waste of an Ear!</title><content type="html">&lt;a href="http://2.bp.blogspot.com/_v5vcOkUEGvc/SfyVsUzWz3I/AAAAAAAAAEY/fxbHH8zB2u4/s1600-h/wispyarm.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5331300647630720882" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 146px; CURSOR: hand; HEIGHT: 200px" alt="" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/SfyVsUzWz3I/AAAAAAAAAEY/fxbHH8zB2u4/s200/wispyarm.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:verdana;font-size:78%;color:#ff0000;"&gt;&lt;strong&gt;[Warning! Make sure you haven’t eaten recently before reading this blog entry.]&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;div&gt;“The Body is Obsolete” is the claim made by freak-show “artist” Stelarc, the Australian entertainer who works primarily in Japan, Europe and the US (What? The Aussies probably can’t drink enough to keep this guy in business in the homeland?) Don’t get your bits in a bunch because I call him an entertainer – his own website offers glimpses into his “performances.” This guy is a definitely a Trekkie gone extreme.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Stelarc’s latest venture includes grafting an ear onto his forearm with plans of implanting a microphone and Bluetooth transmitter into the ear so he can ‘hear’ what his arm-ear is hearing. Why? How far away from your biological ears is your forearm, buddy? Why not implant something really useful like… an iPod? Or maybe a breathalizer? Or a real muscle so you can carry your bags of money to the bank?&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Stelarc’s selection of body part and usage indicates that his is… as we say… an “AOL user.” He could have done some really cool stuff if he knew a bit more about mobile technology and constant need for speed and information. Here are some cyber-bio ideas that I hope to jot off and send to him (under the email addressing of Nurse Chappell, of course):&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;strong&gt;WiFi Interference Arm&lt;/strong&gt;: Implant a Wi-Spy adapter in your arm (complete with antenna). Wire internally to your ‘funny bone’ so you can immediately detect strong WiFi signals or even interference (ouch!) nearby.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;strong&gt;Storage Stomach&lt;/strong&gt;: Since many folks are already getting their stomach’s stapled and all, there my be a bit of extra use to few drives in there – connector would be routed through your belly button so you can jack-in through that nifty belt that connects to your production machine. Hey - maybe we can use skinny people for extra off-line storage for others who have run out of room... hmmm...no wait! Instead of breast implants, we could have 'bits implants' - now that's thinking! Sexy storage!&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;&lt;/strong&gt; &lt;/div&gt;&lt;div&gt;&lt;strong&gt;Voice Recognition Nose&lt;/strong&gt;: Mumble your thoughts and this nose picks up (now it’s doing the picking!) your ramblings and translates it into text format to store on the drive in your stomach or later offloading. (A hypo-allergenic version would be most desirable.)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;I bet you can come up with all sorts of cyber-bio combos that would be &lt;em&gt;waaaay &lt;/em&gt;more handy than an ear/mic in your forearm! Why isn’t this guy taking some classes in technology so he can create something we really WANT to see? &lt;/div&gt;&lt;div&gt;&lt;br /&gt;Just my 2 bits.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:courier new;"&gt;Laura&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-2421372538641654828?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/WBjrrKsZS9I" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2421372538641654828?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2421372538641654828?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/WBjrrKsZS9I/what-waste-of-ear.html" title="What a Waste of an Ear!" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_v5vcOkUEGvc/SfyVsUzWz3I/AAAAAAAAAEY/fxbHH8zB2u4/s72-c/wispyarm.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/05/what-waste-of-ear.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ACSHg8fCp7ImA9WxVXGUU.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-2155992142964997761</id><published>2009-02-17T22:38:00.000-08:00</published><updated>2009-02-18T11:36:09.674-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-02-18T11:36:09.674-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><category scheme="http://www.blogger.com/atom/ns#" term="sharkfest" /><category scheme="http://www.blogger.com/atom/ns#" term="AirPcap" /><category scheme="http://www.blogger.com/atom/ns#" term="CACE Technologies" /><category scheme="http://www.blogger.com/atom/ns#" term="wireshark" /><title>Free AirPcap Adapters at Sharkfest!</title><content type="html">&lt;a href="http://4.bp.blogspot.com/_v5vcOkUEGvc/SZu2rHIOmYI/AAAAAAAAAEQ/P8W1LXh3InY/s1600-h/AirPcap-Tx-and-Classic.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5304033837923080578" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 180px; CURSOR: hand; HEIGHT: 130px" alt="" src="http://4.bp.blogspot.com/_v5vcOkUEGvc/SZu2rHIOmYI/AAAAAAAAAEQ/P8W1LXh3InY/s200/AirPcap-Tx-and-Classic.png" border="0" /&gt;&lt;/a&gt;Two things have been foremost on my plate this week - Sharkfest registration opened and the Chappell University beta program launched. I'll blog about Chappell University next - first, I want to make sure you know how to get a free AirPcap adapter to capture wireless traffic with Wireshark!&lt;br /&gt;&lt;br /&gt;Did you catch last year's Sharkfest Developer and Users Conference? Set in a laid back campus and swarming with Wireshark developers and fantatics, Sharkfest '08 gave us all a chance to mingle, discuss Wireshark tips and tricks, banter about ideas for enhancements and toast to the 10th anniversary and growth of a simple packet capture tool called Ethereal into the industry-leading analyzer Wireshark!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Sharkfest '09 will be held at Stanford University in Palo Alto, California on June 15-18th and CACE Technologies is giving every registered attendee a FREE AIRPCAP CLASSIC ADAPTER! This is a great deal considering the conference is less than $200/day and the initial session offering is filled with basic through advanced analysis techniques for wired and wireless networking.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Check out &lt;a href="http://www.cacetech.com/sharkfest.09"&gt;www.cacetech.com/sharkfest.09&lt;/a&gt; for details on the event and register today to get your free AirPcap adapter!&lt;br /&gt;&lt;p&gt;See you at Sharkfest!&lt;/p&gt;&lt;br /&gt;Laura&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-2155992142964997761?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/gKDQCx2yK00" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2155992142964997761?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2155992142964997761?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/gKDQCx2yK00/free-airpcap-adapters-at-sharkfest.html" title="Free AirPcap Adapters at Sharkfest!" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_v5vcOkUEGvc/SZu2rHIOmYI/AAAAAAAAAEQ/P8W1LXh3InY/s72-c/AirPcap-Tx-and-Classic.png" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2009/02/free-airpcap-adapters-at-sharkfest.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEERHk9eip7ImA9WxRaFUg.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-2585090990090058007</id><published>2008-12-17T13:13:00.000-08:00</published><updated>2008-12-17T13:50:05.762-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-12-17T13:50:05.762-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="brainshare" /><category scheme="http://www.blogger.com/atom/ns#" term="novell" /><title>BrainShare... End of an Era or Time to Change?</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_v5vcOkUEGvc/SUlvVkluYXI/AAAAAAAAAD0/BwvbumXTIKs/s1600-h/bob.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 185px;" src="http://4.bp.blogspot.com/_v5vcOkUEGvc/SUlvVkluYXI/AAAAAAAAAD0/BwvbumXTIKs/s200/bob.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5280874454458458482" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Just moments ago I heard the final decision - &lt;a href="http://www.novell.com/brainshare"&gt;BrainShare 2009&lt;/a&gt; is cancelled. A wave of sadness passed through me... I thought back to the early days at the University of Utah, the Port 'o Call, speaking in the keynote room (just once), Meet the Experts partying, the concerts, the many friends I'd meet just one a year in Salt Lake City, Utah.  &lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Novell's cancellation of BrainShare 2009 definitely marks the end of an era for me - I've presented at every BrainShare since 1998 - since before my kids were born and my hair went grey and I lived in a packet-driven world of analysis. Back in 1998 I was a young whippersnapper skulking around Novell's hallways looking for the secrets behind this networking geek lab. Ray Norda was shuffling his way down the hallway keeping an eye on things and LANalyzer was still a hardware solution owned by Excelan Corporation (which Novell would soon purchase). I was the only girl hanging around the technical support guys (for professional reasons) and truly enamored with the SuperSet guys. &lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Novell's announcement (and Apple pulling out of MacWorld in 2010) are indicative of our need to accept and move to a virtual world in more facets of our lives. &lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;If you got my most recent &lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;newsletter, you saw our &lt;a href="http://www.surveymonkey.com/s.aspx?sm=lLGfv7wphzUEEc7mzH7xjw_3d_3d"&gt;survey&lt;/a&gt; regarding virtual conferences. Times have changed, folks... no training budgets, no travel budgets and likely absolutely no conference budgets in 2009. &lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Can virtual conferences replace physical ones? Can we replace the human interaction and still walk away (albeit only a couple of feet) to feel satisfied that we've learned a lot in our time 'away' from the office? Can we replace the human networking aspect with something just as satisfying personally and professionally? Time will tell. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;Yes... it's the end of an era... or maybe the beginning of something new and exciting... regardless, I want to thank Novell for putting on one hell of a classy show each year - one that I looked forward to participating in swore I would be at until the day they said 'don't come.' &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Laura&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-2585090990090058007?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/n8vZHCLR0Yo" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2585090990090058007?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2585090990090058007?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/n8vZHCLR0Yo/brainshare-end-of-era-or-time-to-change.html" title="BrainShare... End of an Era or Time to Change?" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_v5vcOkUEGvc/SUlvVkluYXI/AAAAAAAAAD0/BwvbumXTIKs/s72-c/bob.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2008/12/brainshare-end-of-era-or-time-to-change.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UAQ3Y8cSp7ImA9WxRUGEg.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-8244475777494530169</id><published>2008-11-27T09:31:00.000-08:00</published><updated>2008-11-27T21:47:22.879-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-11-27T21:47:22.879-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="thermometer" /><category scheme="http://www.blogger.com/atom/ns#" term="Martha Stewart" /><category scheme="http://www.blogger.com/atom/ns#" term="thanksgiving" /><category scheme="http://www.blogger.com/atom/ns#" term="turkey" /><title>Turkey Technology</title><content type="html">&lt;a href="http://3.bp.blogspot.com/_v5vcOkUEGvc/SS7lLQ95d_I/AAAAAAAAADs/A5phs9GeIjQ/s1600-h/turkey.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5273404195393337330" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 125px; CURSOR: hand; HEIGHT: 98px" alt="" src="http://3.bp.blogspot.com/_v5vcOkUEGvc/SS7lLQ95d_I/AAAAAAAAADs/A5phs9GeIjQ/s200/turkey.jpg" border="0" /&gt;&lt;/a&gt; &lt;span style="font-family:arial;"&gt;It's here again... the dreaded 'Turkey Day'. Time to be humiliated in the kitchen once again... &lt;/span&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Three times now I have been thwarted by technology in my attempts to cook the perfect turkey. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;Year 1&lt;/strong&gt;: Bought frozen turkey; put in refrigerator to thaw. Tough getting the thermometer into the dang bird (nearly broke the hammer I used to get it in). After 3 hours, thermometer never moved off '0' - figured the thing was broken. After 4 hours and a nicely browned skin in view, pulled turkey out and dressed it up for serving only to find that the bird must have still been frozen and there were bags o' turkey guts/neck still thawing inside the bird - whoops. Chinese restaurant open today. I am thankful for Mu Shu Pork!&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;Year 2&lt;/strong&gt;: Thermometer got a bad rap last year. Thawed turkey completely; pulled out all bags o' bunk; into the oven it went. After 4 hours and a nicely browned bird, the thermometer wasn't up to the desired 165 degrees. Gave it another 2 hours and it still didn't get to 165... smell indicated something wasn't right. Removed charred and whithered bird and threw away thermometer. Papa John's is open today. I am thankful for pizza!&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;Year 3&lt;/strong&gt;: Martha Stewart's 'high-heat' turkey would only take 2 hours to cook an 18 pounder - no thermometer needed - guaranteed by Martha. Bought the Martha roasting pan, cranked up oven to 475 degrees and threw the damn bird in. Set timer for 2 hours and relaxed with a glass of wine. Determined not to fret over bird. After two hours, opened oven to find the turkey took the heat quite well, but Martha's roasting pan didn't - flakey pieces of some coating material wafted up in the air and was stuck to the outside of the turkey, spotting it with silver 'snowflakes' of faux aluminum or some other toxic substance. Pulled out batch of spaghetti sauce I'd made that morning just in case. MMMM.... a home cooked meal on Thanksgiving! I'm thankful for foresight and decent chardonnay from a local winery. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;This Year&lt;/strong&gt;: After 3 years of humbling experienes and technology failures, friends have stepped up to invite my family to 'stop by' on Thanksgiving. Kids a bit to excited over the idea. Hmmm... Planning on going house to house bringing store-made pies and wine. My family and I will mooch our way through Thanksgiving and hope to spare the life of one turkey this year. No technology to count on other than my car. I expect my friends will share my 'turkey travails' with all the guests - I hear it's a good dinner story... I am thankful for my friends. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;Next Year&lt;/strong&gt;: Premade turkey with lasagna as a back-up (in case the bird doesn't fit in the microwave for reheating - the oven is retired and now stores kitchen items I'll never use again). &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;Happy Thanksgiving to all who celebrate.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Laura&lt;/span&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-8244475777494530169?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/SbmpqsMRLfY" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/8244475777494530169?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/8244475777494530169?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/SbmpqsMRLfY/turkey-technology.html" title="Turkey Technology" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_v5vcOkUEGvc/SS7lLQ95d_I/AAAAAAAAADs/A5phs9GeIjQ/s72-c/turkey.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2008/11/turkey-technology.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D08FRnw_fCp7ImA9WxRVFUg.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-723181426015189392</id><published>2008-11-12T20:49:00.000-08:00</published><updated>2008-11-12T21:56:57.244-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-11-12T21:56:57.244-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Network World" /><category scheme="http://www.blogger.com/atom/ns#" term="Gerald Combs" /><category scheme="http://www.blogger.com/atom/ns#" term="www.chappellsummit.com" /><category scheme="http://www.blogger.com/atom/ns#" term="Summit08 Summit09" /><title>Summit08 Wraps!</title><content type="html">&lt;a href="http://2.bp.blogspot.com/_v5vcOkUEGvc/SRvAtXtDrtI/AAAAAAAAADk/Zv6FImrcGKs/s1600-h/summit09.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5268016074829573842" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 200px; CURSOR: hand; HEIGHT: 55px" alt="" src="http://2.bp.blogspot.com/_v5vcOkUEGvc/SRvAtXtDrtI/AAAAAAAAADk/Zv6FImrcGKs/s200/summit09.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Puff, puff... It's a heck of a lot of work putting on a conference - hats off to the folks who do it year in and year out and actually smile through the process (they must have some strong meds). You are a sick lot, you know! &lt;g&gt;Anyone care to guess how many pieces of bacon, sodas and beers were downed during the two-day Troubleshooting and Security Summit08 conference (November 4-5)? Me neither.  &lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;One of the highlights of the conference was having Gerald Combs (creator of Wireshark) join us to talk about capturing traffic in a virtual environment and Tom Quilty (BD Investigations) talking about the steps to take before and after a network breach occurs. Who ya gonna call? &lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;It was great sitting around a table at the vendor party with those two as well as Ron Nutter from Network World as we swapped geeky war stories and shared some of the inside scoop on cybercrime events and Wireshark development (which are mutually exclusive topics, by the way). He he...&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For those of you who didn't join us, you missed a great time. We played with VoIP reassembly, some ugly WLAN communications, loads of ugly file transfers caused by packet loss/high latency, a DHCP server gone awry, nasty SNMP traffic (that we configured to see using the MIB printer configuration), problems with autonegotiation, SMB2 protocol negotiation during a Vista client/Server 2008 connection, lost packets, totally pathetic websites, evidence of a "DNS walking" application, a redirector infection, SNMP scanning host and traffic hidden through port swapping. &lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Two nights before the conference I added a set of trace files taken at a client and a server - I really wanted to show how to alter the timestamps because one analyzer was off on the timesync and then merge the two traces together, colorizing the two sets to differentiate them. I love this stuff!&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Now my days are spent buiding the Summit 08 Wrap-Up site - if you attended Summit 08 you will receive your login credentials by the end of the week. I've put together four videos covering the MS08-067 vulnerability, the trace file merging process, building and sending custom packets and the Summit 08 Wrap-Up Checklist. In addition, I have a discount code for NetScanTools Pro and Pilot/Pilot+AirPcap EX3 bundle also going up on your Wrap-Up site (you already should have the code for 50% off the Wireshark University self-paced courses - good through December 31st). &lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;So... would we ever do the conference again? Absolutely! We've already started planning based on the feedback we received. Register for notification at &lt;a href="http://www.chappellsummit.com/"&gt;http://www.chappellsummit.com/&lt;/a&gt; and I'll send you an email when Summit 09 registration opens and details on the Early Bird Special pricing. Alumnae will get special discounted pricing on Summit 09. &lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Now... just a couple more days until I head off to Portugal for the Vantagem conference. After that, it's the ATT Live conferences in Salt Lake City and then... well... then it's 2009 and time to start development on Summit 09! &lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Laura&lt;/div&gt;&lt;div&gt;[off to the Wrath of the Lich King launch party... 2 hours and counting...]&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-723181426015189392?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/QekAJj7wzAc" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/723181426015189392?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/723181426015189392?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/QekAJj7wzAc/summit08-wraps.html" title="Summit08 Wraps!" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_v5vcOkUEGvc/SRvAtXtDrtI/AAAAAAAAADk/Zv6FImrcGKs/s72-c/summit09.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2008/11/summit08-wraps.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAASX06fCp7ImA9WxRREk4.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-3719928702160053064</id><published>2008-09-23T20:00:00.000-07:00</published><updated>2008-09-23T22:05:48.314-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-23T22:05:48.314-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="podcasting" /><category scheme="http://www.blogger.com/atom/ns#" term="Network World" /><category scheme="http://www.blogger.com/atom/ns#" term="www.chappellsummit.com" /><category scheme="http://www.blogger.com/atom/ns#" term="MP3" /><category scheme="http://www.blogger.com/atom/ns#" term="pimping" /><category scheme="http://www.blogger.com/atom/ns#" term="Ron Nutter" /><category scheme="http://www.blogger.com/atom/ns#" term="Spore" /><title>Pimping Podcasts and Packets</title><content type="html">&lt;img id="BLOGGER_PHOTO_ID_5249449554030879938" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://1.bp.blogspot.com/_v5vcOkUEGvc/SNnKjn5X5MI/AAAAAAAAACc/JrPPLtrMErI/s200/laurapimp.jpg" border="0" /&gt;Well... with a title like that you just have to read this, don't ya?&lt;br /&gt;&lt;br /&gt;Ok... there are really two subjects here - one is pimping podcasts and the other is packets, but they came together this evening with a new podcast series I am developing and a quick analysis of some podcasting traffic.&lt;br /&gt;&lt;br /&gt;Pimping podcasts? This title came to mind as I searched for some lead-in/closing music for the upcoming podcast series. After searching for royalty-free music for a bit, I found a little ditty that turned my head (including my ears). The music was described as "70's, pimp-stylin, funkin', porn music. If prostitution is a victimless crime, then where's my wallet?"&lt;br /&gt;&lt;br /&gt;I HAD to listen to this music!&lt;br /&gt;&lt;br /&gt;Sure enough - this was some seriously funky music - it dripped of sexual innuendo with loads of &lt;em&gt;wawawa&lt;/em&gt; slipping through &lt;em&gt;dadum dadum &lt;/em&gt;with a funk beat - this could have been background music for Shaft! I could honestly imagine myself following that attitude-adjusting swank with a serious conversation about the If-Modified-Since HTTP header field! What a mood setter!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Note&lt;/strong&gt;: We'll cover the importance of that header field in the upcoming Summit 08 (&lt;a href="http://www.chappellsummit.com/"&gt;http://www.chappellsummit.com/&lt;/a&gt;) when analyzing web browsing traffic.&lt;br /&gt;&lt;br /&gt;So what do packets have to do with this? Well... since I was on the topic of podcasting, I thought I'd check out the traffic rate of the recent podcast I did with Ron Nutter's Help Desk Toolchest over at Network World (&lt;a href="http://www.networkworld.com/podcasts/nutter/"&gt;http://www.networkworld.com/podcasts/nutter/&lt;/a&gt;) - I found that the podcast MP3 file was 31,640,580 bytes and downloaded in just over 30 seconds at an average rate of 8.77 Mbit/s. This was waaaaay bigger than the Internet radio trace I'd taken a while back when studying streaming methods and bandwidth usage. Ron's podcast runs for 65 minutes and 55 seconds. When there I injected traffic into the network to cause packet loss and higher latency, I didn't notice it at all.&lt;br /&gt;&lt;br /&gt;Tomorrow I should finish my analysis of Spore's network traffic and have the signatures to spot and eradicate that little primordial slime off the network (oh, sure... play it at home all you want!).&lt;br /&gt;&lt;br /&gt;Laura&lt;br /&gt;Don't forget - register for the Summit by September 30th for the Early Bird Special!&lt;br /&gt;&lt;a href="http://www.chappellsummit.com/"&gt;http://www.chappellsummit.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-3719928702160053064?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/M5eEWd2GwPM" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3719928702160053064?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3719928702160053064?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/M5eEWd2GwPM/pimping-podcasts-and-packets.html" title="Pimping Podcasts and Packets" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_v5vcOkUEGvc/SNnKjn5X5MI/AAAAAAAAACc/JrPPLtrMErI/s72-c/laurapimp.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2008/09/pimping-podcasts-and-packets.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck4CQHoyeip7ImA9WxRSGEo.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-3727296735610619045</id><published>2008-09-19T17:10:00.002-07:00</published><updated>2008-09-19T17:36:01.492-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-19T17:36:01.492-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Network World" /><category scheme="http://www.blogger.com/atom/ns#" term="www.chappellsummit.com" /><category scheme="http://www.blogger.com/atom/ns#" term="pilot" /><category scheme="http://www.blogger.com/atom/ns#" term="Summit08" /><category scheme="http://www.blogger.com/atom/ns#" term="NetScanTools" /><title>Where the *(@#$# Have I Been?</title><content type="html">It's been ages since my last post - so where on Earth have I been (assuming I've been on Earth, of course). Good question...&lt;br /&gt;&lt;br /&gt;I've been halfway around the world in Canberra, Australia (snoooooooze) and assorted places in the US. Mostly, however, I have been buried in the deep, dark and exotic... lab! Playing around with the VoIP analysis functions in &lt;a href="http://www.wireshark.org/"&gt;Wireshark&lt;/a&gt;, cool enhancements in &lt;a href="http://www.netscantools.com/"&gt;NetScanTools Pro&lt;/a&gt; and wireless views in &lt;a href="http://www.cacetech.com/"&gt;Pilot&lt;/a&gt;. I'm also enjoying playing with systems that have been left naked and exposed on the Internet (eek!) - analyzing the methods used to compromise those systems.&lt;br /&gt;&lt;br /&gt;I've also been writing a series of articles on topics ranging from "Optimize Your Network Regardless of IT Budget Cuts" (&lt;a href="http://www.chappellsummit.com/"&gt;www.chappellsummit.com&lt;/a&gt;) to "Getting More Pool Time (aka Graphing Wireless Network Behavior with Pilot™)" (&lt;a href="http://searchnetworking.techtarget.com/"&gt;searchnetworking.techtarget.com&lt;/a&gt;) and "Enhancing Windows® XP Performance with RFC 1323" (also &lt;a href="http://searchnetworking.techtarget.com/"&gt;searchnetworking.techtarget.com&lt;/a&gt;) and a few podcasts with my friend Ron Nutter were we discussed DNS security faults, strange traffic on the network (check out the live analysis results of going to &lt;a href="http://www.usatoday.com/"&gt;www.usatoday.com&lt;/a&gt; - yucko!), and Microsoft's TCP enhancements in Vista/Server 2008 (all three to air at &lt;a href="http://www.networkworld.com/podcasts/nutter/"&gt;www.networkworld.com/podcasts/nutter/&lt;/a&gt;). &lt;br /&gt;&lt;br /&gt;Most excitingly, however, I've been working on the Student Manuals for the Summit (Network Analysis and Network Forensics Training) that takes place November 4-5 (&lt;a href="http://www.chappellsummit.com/"&gt;www.chappellsummit.com&lt;/a&gt;) - I extended the Early Bird registration price until September 30th because of the hardships caused by Ike and the roller coaster ride we call the Stock Market.&lt;br /&gt;&lt;br /&gt;Over the next two weeks I'll be releasing some of the lab information for the Summit - giving you a taste of the hands-on labs that we'll tackle together. Oh, yeah... we'll definitely do some VoIP playback and work in the wireless world! Join us for accelerated analysis/forensics training at the Summit.&lt;br /&gt;&lt;br /&gt;Better go - it's 5:30pm and I have a few more hours-worth of trace files I want to review this evening! Yippie!&lt;br /&gt;&lt;br /&gt;Laura&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-3727296735610619045?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/E2JwL38OcHk" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3727296735610619045?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/3727296735610619045?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/E2JwL38OcHk/where-have-i-been.html" title="Where the *(@#$# Have I Been?" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><feedburner:origLink>http://laurachappell.blogspot.com/2008/09/where-have-i-been.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUQBSHgyfSp7ImA9WxdbGE8.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-4145894236832137095</id><published>2008-08-15T10:15:00.000-07:00</published><updated>2008-08-15T11:02:39.695-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-08-15T11:02:39.695-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="www.chappellsummit.com" /><category scheme="http://www.blogger.com/atom/ns#" term="Summit08" /><category scheme="http://www.blogger.com/atom/ns#" term="dallas" /><title>Summit 08 Registration Brings Nausea...</title><content type="html">At typical conferences, I only have a 1 hour 15 minute time slot to present information - hardly enough to do more than whet your appetite for packet-level life. It is very frustrating when I really want to ensure attendees grasp concepts and walk out with solid skills for immediate gratification. So... I cancelled most of my remaining conferences this year to focus on development of my Troubleshooting and Security Summit on November 4-5th in Las Colinas, Texas (near DFW).  Visit &lt;a href="http://www.chappellsummit.com/"&gt;www.chappellsummit.com&lt;/a&gt; or &lt;a href="http://www.wiresharku.com/"&gt;www.wiresharkU.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Geez... it takes a ton of work to put on a Summit/Conference! Reviewing the contract with the hotel nearly made me gag! We did select a fantastic hotel and we hope to take over the entire ballroom/meeting room area - giving us plenty of room to spread out with our laptops and great visibility for all attendees. Hey - if you're going to head out and spend time geeking out with us, you might as well be someplace nice (sorry, Detroit Days Inn... I just couldn't do it!).&lt;br /&gt;&lt;br /&gt;I am working on the student kits and the new sets of trace files. I am most excited to work together on the new Microsoft TCP/IP stack stuff, optimization of XP communications and then the compromised host evidence area. In addition, we'll get to work with new trace files of unusual/suspicious traffic to locate their signatures and figure out how to block this crap from the network. Users get more bold every day with the dirty applications they try to run on network!&lt;br /&gt;&lt;br /&gt;There was a major change made from the time we polled the mailing list to the current time - I want to give all attendees a copy of the WSU03: Troubleshooting Network Performance self-paced DVD course instead of the WSU02: Analyzing TCP/IP Communications. The WSU02 stuff is the perfect prerequisite to ensure you get the most out of the conference.&lt;br /&gt;&lt;br /&gt;New trace files - new toys (uh, er... I mean tools) - hands-on labs!  It's gonna be a blast! Make sure you register before September 1st to get the Early Bird Special. Ideally, I'd like to have enough attendees to ensure we take over the hotel.  Oh, yeah - and hotel room discount rates are only available until October 20th.&lt;br /&gt;&lt;br /&gt;Get the full outline and details at &lt;a href="http://www.chappellsummit.com/"&gt;www.chappellsummit.com&lt;/a&gt; and let me know your thoughts!&lt;br /&gt;&lt;br /&gt;Laura&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-4145894236832137095?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/fDSd-orKUTE" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/4145894236832137095?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/4145894236832137095?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/fDSd-orKUTE/summit-08-registration-brings-nausea.html" title="Summit 08 Registration Brings Nausea..." /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><feedburner:origLink>http://laurachappell.blogspot.com/2008/08/summit-08-registration-brings-nausea.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEMGQ3c7fCp7ImA9WxRaEEg.&quot;"><id>tag:blogger.com,1999:blog-7740546072062781853.post-2903239050557975818</id><published>2008-06-30T00:10:00.000-07:00</published><updated>2008-12-11T19:27:02.904-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-12-11T19:27:02.904-08:00</app:edited><title>No One Wipes Blood Off Their Own Face in Movies!</title><content type="html">&lt;a href="http://1.bp.blogspot.com/_v5vcOkUEGvc/SGiKl-mDQZI/AAAAAAAAACU/X1JZnVZ_y2U/s1600-h/bandaid.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5217572553371107730" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://1.bp.blogspot.com/_v5vcOkUEGvc/SGiKl-mDQZI/AAAAAAAAACU/X1JZnVZ_y2U/s200/bandaid.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;Well... it's another late night for me... insomnia rules my world at times and I've spent the day working with the new video training interface and the lab exercises for the Pilot beta course (which is debuting on July 18th - check out the &lt;/span&gt;&lt;a href="http://www.wiresharktraining.com/calendar"&gt;&lt;span style="font-family:arial;"&gt;calendar page&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt; for details). &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;I am finally settling in to watch a movie (oh, and blogging...) - "The Interpreter" is on... a smarmy show with beautiful-but-quesionable-actress Nicole Kidman and amazingly-talented-but-no-one-I'd-let-stay-in-my-house Sean Penn. The scene that just played had Sean Penn grabbing a paper towel, wetting it down and wiping the blood off Nicole Kidman's face. Now why is it that in movies no one can wipe the blood off their own face or put a simple bandage on their cuts? Geez... if we acted the same way I'm sure we'd all be walking around with oozing wounds and blood-stained faces, hands and feet. Ok... Hollywood is not reality (I want you all to remember that when the "Mother of Invention" movie comes out - if it ever does). &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;On that note... I've received numerous queries about the film. Last week I spoke with the main writer - the script is on it's 10th rewrite. He asked me some questions (I'm Technical Consultant on the film) about Navy Seals and intercepting radio-control signals. Now what the hell does that have to do with my life? Oh, wait... I'm not supposed to talk about those jobs... &lt;g&gt;Seriously folks... when the film does come out it will have little relationship to my real life (except for that diaper-packed suitcase scene - believe it or not - that is true). &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;So back to the Pilot labs now - it's just past 12:15 am and I have another 3 hours or so of energy and focus left. I'm excited about this new course - as excited as I am with Pilot. If you don't know about Pilot, check out &lt;a href="http://www.cacetech.com/"&gt;CACE Technologies&lt;/a&gt;' website. I just saved myself about 10 hours creating a report for a customer by using Pilot. &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;Oh... gotta go - final scenes coming up - helicopters and all... hey, wait a minute! I didn't see any helicopters in my film script!!! Time to make some calls... someone in Hollywood's gonna need some Bandaids!&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Arial;"&gt;Laura&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;- Get geeky at www.chappellU.com -&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7740546072062781853-2903239050557975818?l=laurachappell.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsideLaurasLab/~4/hoYhGVBSzfY" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2903239050557975818?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7740546072062781853/posts/default/2903239050557975818?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InsideLaurasLab/~3/hoYhGVBSzfY/no-one-wipes-blood-off-their-own-face.html" title="No One Wipes Blood Off Their Own Face in Movies!" /><author><name>Laura</name><uri>http://www.blogger.com/profile/17667710054709025147</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="17382336285977402506" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_v5vcOkUEGvc/SGiKl-mDQZI/AAAAAAAAACU/X1JZnVZ_y2U/s72-c/bandaid.jpg" height="72" width="72" /><feedburner:origLink>http://laurachappell.blogspot.com/2008/06/no-one-wipes-blood-off-their-own-face.html</feedburner:origLink></entry></feed>
