meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, November 17th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 17 November 2023

⏱️ 15 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Faster tcpdump; Zimbra Exploit Details; FortiSIEM Vuln; AI-Exploits; CrushFTP and FortiSIEM Patches; @sans_edu Research: Scott Poley; Storing Less

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, November 17, 2020,

0:08.0

edition of the Santernet Storm Center's Stormcast.

0:11.0

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:17.0

I did a very brief diary today about TCP dump and, well, how to speed it up a little bit.

0:25.1

So many people are using TCP dump a day in the day out, but you know, you often don't really bother looking at so of the details of the command line options.

0:33.7

The most obvious thing to speed TCP dump up is usually the use of the dash and switch

0:39.5

to prevent reverse lookups. And that's a good idea for a number of reasons, not just for speed.

0:48.4

But there are a couple of other command line options that do affect speed.

0:58.5

And the two that probably matter the most here is Q and T.

1:04.9

Q will just make TisB dump quieter, so basically produce less output.

1:14.5

With that, of course, Tidump also has to analyze less, and that gave sort of about 30% or so a performance gain.

1:16.9

The other option may not be that obvious.

1:17.6

That's T.

1:23.5

T disables display of the timestamp, and the timestamp should be pretty straightforward and simple to analyze, but also sort of gets you a 25 to 30% performance gain if you are

1:33.3

turning off, displaying the timestamp, and then of course best if you disable both

1:39.7

timestamps and run it in quiet mode, which gets you about a 50% speed improvement.

1:48.0

Now, the quiet option is not always appropriate because you really see a lot less details

1:54.6

about the packet, pretty much just sort of IP addresses and maybe ports.

1:59.9

So the T option, I think, is really something to keep in mind if you want to speed up things

2:05.0

a little bit with T-Sb-Dump.

2:07.3

Then this was just a quick test on my M1 Mac.

2:09.9

If you get different numbers, please let me know.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.