Wireshark: An Ethereal Experience

If you love the aroma of network packets, you'll love capturing a snifter full of your favorite network-scented morsels with Wireshark, the world's most popular network protocol analyzer.

On a scale of one to ten, where one is dental surgery and ten is winning a $100 million Powerball lottery, network protocol analysis falls somewhere in the range of three or four. It isn’t exactly painful but it certainly doesn’t arouse any fireworks or thoughts of fireworks in your soul. Wireshark, however, makes network packet sniffing and analysis easy and almost fun.

Wireshark is a network protocol analyzer tool, which means that it captures and interprets live network traffic data for offline analysis. Sometimes referred to as packet sniffing, packet analysis helps you understand what’s going on network-wise so that you can assess and mitigate problems with bandwidth, security, malicious activity and normal network usage.

Wireshark is free software licensed under the GPL.

The Basics

To install Wireshark and its dependencies on Debian-based systems, enter the standard apt-get bandy.

$ sudo apt-get install wireshark

For rpm-based systems, enter the equivalent yum command.

$ sudo yum install wireshark

On some systems, you might be surprised when you look for Wireshark under Applications ->Internet and you don’t find it. Nor do you find it by entering wireshark & in a terminal window. These systems install the non-GUI applications such as tshark, editcap and rawshark sometimes known as wireshark-common components. To install the familiar Wireshark GUI, refer to wireshark-gnome or wireshark-gtk+ in your install command.

Download the source code from the Wireshark Download page and compile in the usual way, if you’re not satisfied with pre-built binaries. There are a few dependencies needed for a source code compilation but the configure script informs you of these as it proceeds and fails.

Using Wireshark

Once installed, you’ll want to jump right in and start sniffing away at your network traffic. You might run into a roadblock or two if you “jump this shark” too quickly. For one, you have to use a privileged account, such as root, that has the ability to place one or more of your network interfaces into promiscuous mode. Second, you must perform a bit of configuration prior to gathering your data. Let’s look at a simple session.

Open Wireshark by locating its icon under Applications->Internet (GNOME). As Figure 1 shows, Wireshark is a typical-looking GUI application.

Figure 1: Getting Started with Wireshark Capture Options
Figure 1: Getting Started with Wireshark Capture Options

To configure a capture, click Capture from the menu and then select Options to launch the Capture Options entry screen. See Figure 2.

Figure 2: Configuring Wireshark for a Capture Session
Figure 2: Configuring Wireshark for a Capture Session

Comments on "Wireshark: An Ethereal Experience"

paulquater

check this out for packet dump parser: http://www.networktimeout.com

Reply
lazylogic

Setup as you’ve suggested but am unable to capture the network traffic of another computer(netbook).

My setup :
Laptop installed with wireshark (192.168.1.201)
Netbook is the test subject (192.168.1.202)

Steps:
Boot netbook and connect it to wireless router using wpa2. Surf to different sites non stop.
Boot laptop and start wireshark capture as advised.

Results:
There is no traffic captured by wireshark for netbook. Only traffic of the laptop itself.

Reply
robhwill

Thanks for article. Am I missing something or is there no option for ‘print’ or ‘printer-friendly’ so can save/print article?
Have A Healthy, Prosperous Day!
—rob

Reply

Generally I don’t read post on blogs, but I wish to say that this write-up very forced me to check out and do so! Your writing style has been amazed me. Thanks, very nice post.

Reply

Definitely would love to start a website like yours. Wish I had the time. My site is so amateurish compared to yours, feel free to check it out: http://tinyurl.com/o55af8p Alex :)

Reply

These guys Previously used to Laugh about japan – But Now I actually laugh at all of them

Reply

Cornhole bags are an essential part of the game and are how you score points.

Reply

Examples Of The Approach That Is Also Helping bag-professionals To Grow

Reply

Apply a tiny, just sufficient to accomplish the job, but not too much.

Reply

What we ought to do to discover women well before you’re abandoned.

Reply

L’abus d’alcool se trouve rrtre devenue rare nouvelle personne spéciale

Reply

The next formula for men you are able to discover more about right away.

Reply

This piece of writing gives clear idea in support of the new viewers of blogging,
that in fact how to do running a blog.

Reply

Development- watch Will Play An Important role In Any Organization

Reply

Variety of advantageous approaches to discover women well before you are abandoned.

Reply

It’s possible that You Also Make These kinds of Goof ups With bag ?

Reply

Cutting edge men Book Shows you The Simplest Way To Dominate The men Market

Reply

Most likely You Also Make The following Mistakes With bag !

Reply

He finally made it to the big leagues by

cheap oakley sunglasses outlet http://fermanicannucce.it/?cgi=cheap-real-oakley-sunglasses-bjI9ab.html

Reply

What should have been taken as an insult as turned into a benefit

cheap oakley sunglasses outlet http://cieffeilluminazione.it/?cgi=oakley-sunglasses-outlet-online-JgabG4.html

Reply

time off for the birth of his second child

cheap oakley sunglasses online http://www.comboniane.org/doc/?cgi=cheap-oakley-glasses-for-sale-YabS1v.html

Reply

who had a one-shot lead going into the third round

cheap oakley sunglasses outlet http://www.forcedimension.com/betasite/cheap-oakley-sunglasses

Reply

last year and had to use an exemption

cheap oakley sunglasses outlet http://stefanmalzkorn.de/?cgi=discount-oakley-sunglasses-outlet-3SF3ab.html

Reply

An overview of the watch that one can cash in on beginning today.

Reply

Nice celine shoe, shipped quickly, seller recommended!!!

Reply

Wireshark: An Ethereal Experience | Linux Magazine

Reply

The actual fundamentals behind watch which you may make money from beginning today.

Reply

B2B means ‘business to business’, and nowadays, many B2B web portals emerged in china and
abroad. Becker Shoes is a leading online shoe stores Canada offering a wide selection of designer shoes.
Knowing what motivates people to buy products and
services can positively impact your bottom line.

Reply

You can find some very elegant things in Ann Taylor.
You won’t have to manufacture or buy goods and keep them in your
storehouse; all you need in providing services are
people who are capable of doing their jobs efficiently.
Sport styles from Japanese Streetwear to Sophisticated
Urbanwear for teenage and young adult fashionistas
who are ‘kawaii’ or cute.

Reply

Info- watch Will certainly Have An Important role In Any Organization

Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>