Talk about putting your money where your mouth is!
You're viewing a single comment thread. View all comments, or full comment thread.
Comments (57)
sorted by:
That's too bad. I was going to ask you to report back with your analysis.
If anyone gets wind of a copy of the files being made available, I would definitely perform a proper analysis and create a report. I'd love a chance to do my bit.
Faking pcaps files is almost impossible with any kind of volume. The timings and packet sequences would be easy to spot if they were out of sequence.
In addition, if there are missing 'retries' then that would indicate that the files had been filtered first etc. (i.e. so not raw).
I'm a qualified expert in the field.
In addition to what you stated (which is 100% true; TCP protocol), the fact that they are all TLS packets with origination certificates and fully decrypted... It's virtually impossible to fake this. How they managed to MITM all of this is really an amazing achievement.
See, this is so far from being my forte, I love it that we have frens here with that type of knowledge. I hope you do get your hands on the info and if you do, that you report back. I would be very interested to hear your take. Thanks.
I'm tempted to tell you the kind of knowledge I have, but it would make it too easy for someone in the know to work out who I was, even without IP logs.
And then you'd hafta kill us.
That's alright, fren. It's a shame it has to be that way. Maybe someday .. soon-ish.
It’s so far from my forte that I don’t even know PCAPS are, lol. Not that I even have a specific skill/forte anyways. I to appreciate the folks here that do have an abundance of knowledge to share. I’m happy to have found this forum, if it wasn’t for everyone here I’d probably have gone crazy by now thinking I was the only one seeing what a clown world we are living in right now.
fyi a pcap file is basically a full copy of every data packet on a network that has been captured.
It includes a lot of details that most people aren't aware, including timestamps down to thr millsecond and encryption details etc.
Yup. But everybody has a forte, maybe you just haven't found yours yet. If so, you will.
I can assist with this, DM me if you get your hands on anything and I'd be happy to chip in and do my part as well
I'll bear that in mind, thanks