Re: [tcpdump-workers] pcap anonymizer

2011-05-02 Thread Seth Hall
On Apr 30, 2011, at 12:10 PM, Aaron Turner wrote: > Honestly, I'm not aware of any tool which covers every possibility so I hate to even mention this, but Bro-IDS' current release (1.5.x) can do this because as you mentioned, information is leaked through many application protocols and you can

Re: [tcpdump-workers] only outbound traffic

2011-05-02 Thread Seth Hall
On Apr 29, 2011, at 3:34 AM, Andrej van der Zee wrote: >> On Apr 29, 2011, at 2:13 AM, Guy Harris wrote: >> Why would an "offset" keyword be better in the filtering language than, say, >> the "vlan" keyword it already has? You'd still have to do the same sort of >> special stuff, but it'd be a

Re: [tcpdump-workers] pcap anonymizer

2011-05-02 Thread Stephen Donnelly
On 29/04/11 19:12, Guy Harris wrote: On Apr 28, 2011, at 3:31 PM, Michael Richardson wrote: Unless someone says that there is something else out there, I'm going to write an (IPv4) pcap file anonymizer. I won't make the first version efficient. The Internet Traffic Archive has some anonymizin