Show HN: Wireshark as a web app
cloudshark.org
cloudshark.org
Other questions I'd ask: how well does it integrate with SIEMs like ArcSight? What about larger bandwidth needs, like for 10-gig networks? Can I extend the storage? How quickly does it actually search?
I've bookmarked their site for later review.
("How well does it integrate with ArcSight"? Sheesh.)
The ability to make this into a collaborative tool is great -- I'd love to turn this into a protocol reversing tool where I can work with people in real time to figure things out.
Edit: Just noticed it's not open source. That's a real shame, but hopefully someone will use this as inspiration for an open, flexible tool with the same concept.
Instead, places like GitHub and the like need to get smarter about what they are actually storing and facilitate collaborative analysis that way.
That's at least one use case I can imagine.
Caveat: of course, my comment itself is negated in the case of a call-center that's has a poorly designed storage network.
I found modern web UI is really much more advance than what existing desktop UI implementation. I was thinking of making a wrapper app around tcpdump/pcap app and generates a nice Web UI for localhost user.
Only if you have a better idea on how to display the data, and then I as a user don't care about the technology you use to implement it. Implementing the same UI in HTML/CSS is not more useful than implementing it in a native toolkit.
Oh, and writing it using web technologies might be easier, but there's nothing you can do with them that you can't do with a native desktop implementation, for the simple fact that browsers themselves are native desktop applications.
That is a rather bizarre claim.
I meant "modern web UI is more advanced than desktop UI".
Like what Jeff Atwood said before in 2007.
http://www.codinghorror.com/blog/2007/06/who-killed-the-desk...
Edit: Seems to work really well as viewer for Shark for Android. Although I do agree with the security concerns it's still a very cool product.
http://www.commandlinefu.com/commands/view/4373/analyze-traf...
http://mkjon.es/cloudshark-slow.png http://mkjon.es/cloudshark-fast.png
That being said, I wish it had a demo dataset to work with. I'm kind of regretting uploading packet dumps (even restricted to one remote IP / port) given that they contain my mac address / my router's mac address. I don't think I'll use this for much in the future just because pcaps usually contain private data. I guess that's why they charge for the on-site software / device.
They need a Security story other than "run it on an appliance inside your network." I would also appreciate a single page (unless I missed it) that explains the Analysis value-adds.