<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Network Forensics &#8211; Extracting audio, video and other binary data from capture files</title>
	<atom:link href="http://michaeldundas.com/2008/10/17/network-forensics-extracting-audio-video-and-other-binary-data-from-capture-files/feed/" rel="self" type="application/rss+xml" />
	<link>http://michaeldundas.com/2008/10/17/network-forensics-extracting-audio-video-and-other-binary-data-from-capture-files/</link>
	<description>Precision, Integrity, Communication</description>
	<lastBuildDate>Fri, 30 Mar 2012 09:51:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Michael Dundas</title>
		<link>http://michaeldundas.com/2008/10/17/network-forensics-extracting-audio-video-and-other-binary-data-from-capture-files/comment-page-1/#comment-17</link>
		<dc:creator>Michael Dundas</dc:creator>
		<pubDate>Wed, 03 Dec 2008 22:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://clear2go.wordpress.com/2008/10/17/network-forensics-extracting-audio-video-and-other-binary-data-from-capture-files/#comment-17</guid>
		<description>Erik.&lt;br/&gt;&lt;br/&gt;Thank you for the comment.  I will review network miner.  I like open source forensic tools and love seeing progress in their development and use.  I also feel that is is important that individuals are armed with a detailed understanding of how things work, which can be a problem if it is just a &#039;tool&#039; they use.  Technical understanding is important especially for credibility in court or in front of a executive team.  To say &quot;I did this with product X&quot; is one thing, but you get more credibility if you can explain that this is how it actually works, and how the product does it.&lt;br/&gt;-mike</description>
		<content:encoded><![CDATA[<p>Erik.</p>
<p>Thank you for the comment.  I will review network miner.  I like open source forensic tools and love seeing progress in their development and use.  I also feel that is is important that individuals are armed with a detailed understanding of how things work, which can be a problem if it is just a &#8216;tool&#8217; they use.  Technical understanding is important especially for credibility in court or in front of a executive team.  To say &#8220;I did this with product X&#8221; is one thing, but you get more credibility if you can explain that this is how it actually works, and how the product does it.<br />-mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erik</title>
		<link>http://michaeldundas.com/2008/10/17/network-forensics-extracting-audio-video-and-other-binary-data-from-capture-files/comment-page-1/#comment-16</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Wed, 03 Dec 2008 12:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://clear2go.wordpress.com/2008/10/17/network-forensics-extracting-audio-video-and-other-binary-data-from-capture-files/#comment-16</guid>
		<description>There is a much better application available for extracting transfered files from PCAP&#039;s. The tool is called &lt;a HREF=&quot;http://networkminer.sourceforge.net&quot; REL=&quot;nofollow&quot;&gt;NetworkMiner&lt;/a&gt; and is available at SourceForge.net.&lt;br/&gt;&lt;br/&gt;There is also a description for how to go about in order to dump media files (video, music etc.) to disk without first creating a pcap file. The description is available at the &lt;a HREF=&quot;http://networkminer.wiki.sourceforge.net&quot; REL=&quot;nofollow&quot;&gt;NetworkMiner wiki&lt;/a&gt;:&lt;br/&gt;&lt;br/&gt;&lt;a HREF=&quot;http://networkminer.wiki.sourceforge.net/save+media+files&quot; REL=&quot;nofollow&quot;&gt;http://networkminer.wiki.sourceforge.net/save+media+files&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;NetworkMiner is, however, a Windows application. But you can run it under *nix OS&#039;s by using Wine. Check this blog post out: &lt;a HREF=&quot;http://geek00l.blogspot.com/2008/12/drunken-monkey-running-network-miner.html&quot; REL=&quot;nofollow&quot;&gt;Drunken Monkey: Running Network Miner with Wine&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>There is a much better application available for extracting transfered files from PCAP&#8217;s. The tool is called <a HREF="http://networkminer.sourceforge.net" REL="nofollow">NetworkMiner</a> and is available at SourceForge.net.</p>
<p>There is also a description for how to go about in order to dump media files (video, music etc.) to disk without first creating a pcap file. The description is available at the <a HREF="http://networkminer.wiki.sourceforge.net" REL="nofollow">NetworkMiner wiki</a>:</p>
<p><a HREF="http://networkminer.wiki.sourceforge.net/save+media+files" REL="nofollow">http://networkminer.wiki.sourceforge.net/save+media+files</a></p>
<p>NetworkMiner is, however, a Windows application. But you can run it under *nix OS&#8217;s by using Wine. Check this blog post out: <a HREF="http://geek00l.blogspot.com/2008/12/drunken-monkey-running-network-miner.html" REL="nofollow">Drunken Monkey: Running Network Miner with Wine</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

