Wireshark for security and mitigation.
In this blog: Wireshark in the security setting. The TCP handshake. What are DOS attacks? SYN flood attacks. Uncovering SYN flood attacks. Uncovering geo-location of DOS attacks. Map view. What's next? See my blog on Wireshark basics here. See my blog on my favourite Wireshark alternative (TCPdump) here. See my blog on DOS attacks here. See my blog on SYN flood attacks here. Wireshark in the security setting Wireshark can be used as a network trouble-shooter and as a tool for hackers to carry out attacks such as ARP poisoning or SYN flood attacks (also known as Denial-of-Service attacks). The platform can also be used by security researchers to find evidence of such attacks taking place on the network layer. As a packet sniffer, Wireshark can listen for packets but cannot send any out which means it is not a vulnerability scanner. However, it can display packets in real time and offer insight on how each source IP interacts on the network. ...