2012-11-14 01:46 PM
Is there any way to decode base64 encoded files from within Investigator other than resorting to outside tools? I've tried opening the session in Wireshark, but base64 decoding seems to be broken under Windows. Any suggestions?
My solution thus far has been to:
Anything shorter or simple?
Thanks,
Charlie
2012-11-16 04:49 PM
Investigator will automatically convert base64 attachments in emails when extracting files from a session. Are you using the "extract files" capability? All this depends on your parsers correctly identifying the service type of the session.
What types of traffic are you seeing base64 files? Generally speaking, protocols that contain content-type information are automatically handled.
2012-11-16 04:49 PM
Investigator will automatically convert base64 attachments in emails when extracting files from a session. Are you using the "extract files" capability? All this depends on your parsers correctly identifying the service type of the session.
What types of traffic are you seeing base64 files? Generally speaking, protocols that contain content-type information are automatically handled.