Wireshark-users: Re: [Wireshark-users] Anonymising PCAP files with Wireshark?
From: Kevin Cullimore <kcullimo@xxxxxxxxxx>
Date: Wed, 25 Jan 2012 18:24:37 -0500
On 1/25/2012 9:45 AM, Grégoire, André wrote:

Hi Everyone,

 

What is the best way to anonymize pcap files? Mainly substitute a real IP address and mac address for a fake one.

 

There seems to be a lot of scripts out there that change one or the other but I am looking if something is generally accepted as best practice or tried tested and true by this community.

As of Sharkfest 2011, that appeared to be a work-in-progress, but the emerging consensus regarding the scope of the problem included factors beyond header interface addresses.

 

Thanks for your time, it’s appreciated.

 

Andre

________________________________

Andre Gregoire

Senior Enforcement Officer

Electronic Commerce Enforcement

Canadian Radio-television and Telecommunications Commission (CRTC)

andre.gregoire@xxxxxxxxxx

Telephone 819-953-6972

Government of Canada

 



___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe