9 ms·
WireEdit – A Full Stack WYSIWYG Editor for Network Packets
- pritambaral 12y agoNo native Linux support (Win7 binary "+ hacked version of WINE"). Makers request it be run on "Ubuntu 14.4 x32"[sic] only, not even x86_64. I suspect they mean x86, or 32-bit when they say x32, since the x32 ABI is nowhere near implemented. No source, no privacy policy. Supporting new protocols/formats/stack requires one 'to talk about it' with them.
- wirefloss 12y ago1) Have Ubuntu12.04x32 with hacked WINE working as well. Let me know if you need it. 2) No source indeed. 3) Privacy policy is stated in the EULA. I'll repeat it here: "No info is gathered, no connections to outside servers, except for a standard WINE repository".
- cbd1984 12y agoWithout source why should we trust the privacy policy?
- pyre 12y agoPresumably the crowd that a packet editor is targeted at knows their way around something like WireShark, and could easily monitor the software for phoning home. That's a pretty strong incentive to not do it.
- wirefloss 12y agoOne would think so. I'm certainly curious how much people use the tool. Wouldn't you? However in anticipation of security concerns the software doesn't gather any info, and makes no external connections. Auto-updates were implemented, but later disabled for the same reason.
- cbd1984 12y agoSo now I have to keep tabs on the behavior of my tools, in addition to everything else I have to keep tabs on?
- pyre 12y agoI was stating that within the crowd of people that such a tool is targeted at, someone will run a packet sniffer against it. The likelihood of this happening is high. This is a severe disincentive for someone to 'phone home' if they plan to keep making money from said group of people. As soon as someone runs a packet sniffer and finds something suspect, the whole thing falls apart. But no, you don't have to keep tabs on it, because you don't have to use this tool. If you do choose to use this tool, you can play the probabilities and more than likely be fine.
- cbd1984 12y agoOK, how do we know it doesn't install something that will phone home when nobody's using the program? A little cron job or something similar.
- wirefloss 12y agoYou'd have to make an intelligent decision without access to full information. Isn't it often like that in life? As an engineer myself, I'd respect any decision you make.
- cbd1984 12y agoWhat assurances do we have that you'll live up to your privacy policy?
- wirefloss 12y agoI'm afraid there is no such thing. Even open source products have critical security bugs as you may very well know. If you do just a bit of research you can find who I am, and where I live. Code is not obfuscated. This is the best I can do.
- cbd1984 12y ago> Even open source products have critical security bugs as you may very well know. Except they get fixed without someone threatening to disclose them. > If you do just a bit of research you can find who I am, and where I live. What do you expect me to do with that information? I'm being honest: I don't really get what that information would do for me if I found your code was doing something wrong, unless I thought it was worth my time to file a lawsuit. > Code is not obfuscated. We have very different definitions of this term. > This is the best I can do. Examples exist which show this statement to be wrong.
- cbd1984 12y agoDownvoting me doesn't make my comments less true.
- pyre 12y ago> 1) Have Ubuntu12.04x32 with hacked WINE working as well. I think that the parent was more concerned with the lack of 64-bit (x64/AMD64/x86_64) support. The parent also takes issue with the usage of x32 to refer to 32-bit.
- wirefloss 12y agoAdded the stated above privacy policy to website FAQ.
- wirefloss 12y agoToday it's x86 only.
- jobposter1234 12y agoThis looks really cool. Whenever I open up my Networks textbook, I get nostalgic about this stuff. It'd be fun to easily create my own packets to test out different stuff I've learned. ... any idea on a Mac version?
- simlevesque 12y agoYou should add the licence on the website. It's a nice concept but I'll start using it as soon as someone creates a FOSS clone.
- wirefloss 12y agoPrivacy policy added to the website FAQ. No data is gathered, no connections to the outside, except for a WINE repository for Ubuntu install.
- swartkrans 12y ago>It's a nice concept but I'll start using it as soon as someone creates a FOSS clone. I like FOSS, and am grateful for the work open source engineers put into software, and I have also contributed, but this attitude right here where you wont even consider something because it's closed source? What's the point of that? Why shouldn't an engineer be paid? It's very difficult to capture value with open source software. Please explain to me how they could monetize this on par with the effort put into developing this and still have it be open source. This isn't a service that runs in a website, this is something you download and run.
- develop7 12y ago> Why shouldn't an engineer be paid? shouldn't he? EDIT: fixed bad wording. sorry, English is not my native. > Please explain to me how they could monetize this on par with the effort put into developing this and still have it be open source. paid closed-source plugins supporting enterprisey protocols, paid support, custom functionality. these are from top of my head, so pretty sure wirefloss devs could think of something as well.
- Arkanosis 12y agoCan't tell for others, but I'm very reluctant to spend time learning a tool that I know from the beginning I won't be able to debug / improve later and that the owner may change in a way that doesn't fit me or even stop to support. The only non-FOSS tools I've been using on a daily basis for years are Gmail and Google Calendar. I can't tell I'm really happy with how they have evolved out of my control. Oh, and Google Reader — you know what happened to it… And it's really not about money. I'd be happy to pay a developer for some tool I use everyday if asked for. I already pay for music under CC or FAL.
- xorrbit 12y agoNot open source = not at all like WireShark, sorry. And that's a damn shame. I could see a community growing around this kind of thing and adding all kinds of protocol support to it, if only it was open source.
- wirefloss 12y agoNo competition with WireShark is intended. WireEdit is a packet editor, not an analyzer. Can as easily edit a .txt Hex dump of a packet (not yet supported, but easy to do).
- rudolf0 12y agoI will admit that I initially thought this was a Wireshark plugin or related to Wireshark in some fashion, based on the name and the appearance of the GUI on the page. You may want to put a little disclaimer at the top saying it's not associated or competing with Wireshark. Pretty cool tool either way.
- pyre 12y agoDon't know if it was just added, but the front page currently has this on it: Are you competing with Wireshark? No. WireEdit is a packet editor, not an analyzer. No real-time packet capture either.
- wirefloss 12y agoYeh. I added it after the above question was asked. It was asked once, so it obviusly belongs to a FAQ.
- jnazario 12y agoif you're looking for an OSS variant of this (packet editor with a GUI), have a look at Netdude: http://netdude.sourceforge.net/ http://netdude.sourceforge.net/ older package, but does basically this.
- danra 12y agoLooks awesome. Waiting for the Mac version :)
- dchichkov 12y agoI'm curious how it deals with field lengths, conditional fields and other constraints. It is tough to get it right ;) Try comparing it with: http://freestuff.linkbit.com/epc_packet_builder/ http://freestuff.linkbit.com/epc_packet_builder/ edit Ah.. Wait http://www.wirefloss.com/ http://www.wirefloss.com/ This one looks very familiar :)
- deleted 12y ago[deleted]
- abcd_f 12y agoVideo's too tall, doesn't fit on my relatively run-of-the-mill Thinkpad Edge screen. Just FYI.
- wirefloss 12y agoI know. Sorry. Can't fix at the moment, will do later. Try to decrease the width of the browser, the video frame will decrease proportionally. Hope that helps.
- csmajorfive 12y agoYou can just watch it directly on YouTube. https://www.youtube.com/watch?v=Mp1hpMOjk6c https://www.youtube.com/watch?v=Mp1hpMOjk6c
- pyre 12y agoSame here. MacBook Pro 15" Retina screen: http://imgur.com/fmtqXFD http://imgur.com/fmtqXFD
- ParvusPonte 12y agoJust in case anyone's wondering, you can replay the results as spoofed network traffic via tcpreplay: https://github.com/appneta/tcpreplay https://github.com/appneta/tcpreplay or rather tcpliveplay (that should be included in the package), unless you decide modify tcp packet order numbers manually. A very useful tool for any kind of low level network development, especially multiplayer games.
- anExcitedBeast 12y agoVery cool! I've been wanting something like this for a while. Going to make my life easier. I think it'd be great if you could implement a plugin feature so people could import custom protocols.
- chappar 12y agoI am curious what you would be using this for
- owenversteeg 12y ago> Edit L1 - L7 with just a few clicks Damn, still nothing that can help me with my layer 8 problems.
- lucb1e 12y agoI am guessing you mean the user? - /me googles - Indeed, haha :)
- Matumio 12y agoA similar (non-GUI) tool is scapy: http://www.secdev.org/projects/scapy/demo.html http://www.secdev.org/projects/scapy/demo.html
- Tepix 12y agoI'm super excited about WireEdit, I hope they will provide a version that runs with 64bit Linux, too.
- reitanqild 12y agoRelated: do someone around here know a tool for automatic or assisted reverse engineering? I sometimes work on reverse engineering and something that could help me make sense of it would be greatly appreciated.
- digital-rubber 12y agoHmm precompiled binaries and running things under wine for linux.. Another 'great' post on hacker news. -1 thank you.
- lucb1e 12y agoI was very excited, it's a project I've been wanting to do for years but never had the time (or better yet, something I've wanted to use, but it never existed). Then I got to the downloads. Great, an Ubuntu version... which is just the Windows version bundled with WINE except they modified WINE... and in the README they warn that it really only works with Ubuntu x32 and that you shouldn't have WINE already installed. Right. Why they expect people to still run x32 in 2014 is a mystery to me, but these guys do. And I already have WINE installed. At this point I started to feel really bad about giving this my root password (the readme said it would prompt for it), it all just sounds super hacky. Also the instructions to place it in my home directory... why, doesn't it work elsewhere? What kind of epic hack is this? No, I don't think I trust this with root permissions.
- wirefloss 12y agoYou can install from any folder, not only your home folder. Most package installations under Linux do require sudo privileges, so WireEdit is in no way unique. You password is SAFE. Really. The README is trying to be pretty upfront about what it is, and how it works. See also my replies to other questions here.
- MichaelGG 12y agox32 or x86? Cause X32 is the 32-bit-on-x86_64 ABI so you can get the benefit of the AMD64 instruction set and registers but without the overhead of 64-bit pointers. (Of course you can't access beyond 4GB RAM.) X32 is faster at some things, but it doesn't seem to have much support. But it would be a good idea for many things, like desktop apps that don't need a lot of memory.
- wnevets 12y agoGoogle chrome didnt like this download at all, telling me its a virus.
- wirefloss 12y agoIt's not. I use Chrome all the time. It may be the zip file which spooks it. The zip contains an .msi file + a folder with pcap examples. If you wait a couple of hours, I'll put a separate .msi for download.
- wirefloss 12y agoYou can now download the .msi installer separately. Not sure it'll make Chrome happy. If you want the folder with Pcap example files, download Ubuntu version, and tar xvf it. It still has the examples folder inside.
- wnevets 12y agoThanks for the effort. Chrome is actually throwing a "Uncommon" warning on both files, which I guess is better than a malware warning. https://support.google.com/chrome/answer/4412392?p=ib_download_blocked&rd=1 https://support.google.com/chrome/answer/4412392?p=ib_downlo...
- smutticus 12y agoI'm the author of the packet editor Hexcap. http://www.hexcap.org http://www.hexcap.org Hexcap is an ncurses packet hex editor and generator, and it's open source. It uses the dpkt library for packet encap and decap, as well as dnet and pypcap for capturing and transmission. It's probably not as fancy as WireEdit, but then again the intended audience is different. I started writing Hexcap, in ESR's terms, to scratch my own itch. I'm a grad student which means Hexcap goes for long periods without updates. But when breaks roll around I usually find time to hack on it. If this kind of thing interests you, I'd be interested in hearing about your opinion of Hexcap. Typical FOSS disclaimers applying, YMMV.