Wireshark-dev: Re: [Wireshark-dev] Tools to anonymize pcaps with cellular/3gpp traffic

From: Ivan Nardi <nardi.ivan@xxxxxxxxx>
Date: Thu, 8 Jun 2017 20:55:30 +0200
Hi all
thanks everyone for your replies and for reporting your valuable
experience on this topic.
I knew that I was asking for too much but I'll take a look at the
programs that have been named.

Cheers
Ivan



On 7 June 2017 at 20:54, Ivan Nardi <nardi.ivan@xxxxxxxxx> wrote:
> Hi
> There are a few public available tools that anonymize pcap files, but they
> usually target L2-L4 layers and "standard" protocols (i.e. dns, icmp,...)
> Is there any tool which sanitizes information carried on "3gpp" protocols
> (ranap, bssap, gsm_a dtap, gsm_map, sgsap...) or, at least, on some of them?
>
> I am not looking for something particularly advanced: zeroing mcc and mnc
> (both in imsi and in cell/location information) should be enough, even
> without checksum updating.
>
> The goal is to easily share some pcaps without changing them with an
> hex-editor by hand
>
> I know that I am asking for a very specific tool, but it's worth giving it a
> try...
>
> Thanks in advance
> Ivan