HakTip 115 – Wireshark 101: How to Wireshark
On this HakTip, Shannon Morse breaks out Wireshark for a beginning look at the packet sniffing tool.
Today we’re starting a short series on Wireshark! Hopefully, by the end of this series, you’ll understand most of the basics of Wireshark and be able to solve many problems.
If you’re thinking “Hey Hak5, you’ve done this already! You’re right! Kind of. We have used Wireshark in the past for several segments, and I did a short intro video back on episode 64 of HakTip, but now, we’ll really delve into it.
First off, a little bit of review: Wireshark is a network analyzer for Windows, Mac Linux- a tool that is used to inspect data passing through a network interface, be it your Ethernet LAN or even Wireless radio. This can also include radios! These bits of data are considered Frames, of which include “packets”. Wireshark has the ability to capture all the packets that are sent and received over your network and decode them for analysis.
These packets are made up of all sorts of data, from browsing history to keylogs. Wireshark can find all these packets sent over TCP/IP. Wireshark is available to download for free at Wireshark.org.
For this series, I will be using Wireshark on my Windows 8 laptop – an Acer Aspire S7. It runs pretty much the same on all other operating systems. On today’s episode, we’ll start looking at the graphical user interface and introduce you to what the heck a packet capture is!
Firstly, when you open Wiresark, there’s a couple of toolbars at the top, an area called Filter, and a few boxes below in the main window. Online directly links you to Wiresharks site, a super handy user guide, and information on the security of Wireshark. Under Files, you’ll find Open, which lets you open previously saved captures, and Sample Captures. You can download any of the sample captures through this webpage, and study the data. This will help you understand what kind of packets Wireshark can capture.
Lastly is the Capture section. This will let you choose your Interface. If I click on mine, you can see each of the interfaces that are available for me to sniff on. It’ll also show you which ones are active – mine is on Wi-Fi, so it is most active. Clicking details will show you some pretty generic information about that interface.
Under Start, you can choose one or more interfaces to check out. Capture Options allows you to customize what information you see during a capture. Take a look at your Capture Options – under here you can choose a filter, a capture file, and more.
Under Capture Help, you can read up on how to capture, and you can check info on Network Media about what interfaces work on what platforms.
Let’s go ahead and run our first packet capture. I chose Wi-Fi, and click Start.
You’ll see a bunch of weird stuff flying through your Wireshark window. During my capture, I browsed the web a bit and logged on to a few sites. To stop a capture, press the red square in the top toolbar. If you want to start a new capture, hit the green triangle which looks like a shark fin next to it. Now that I’ve got a finished capture, I can click File, and save, open, or merge the capture. I can print it, I can quit the program, and I can export my packet capture in a variety of ways.
Under edit, I can find a certain packet, with the search options, I can copy packets, I can mark (highlight) any specific packet, or all the packets. Another interesting thing you can do under Edit, is resetting the time value. You’ll notice that the time is in seconds incrementing. You can reset it from the packet you’ve clicked on. I can add a comment to a packet, configure profiles and preferences.
Now, I’m giving you homework! Install Wireshark and run your first capture. It doesn’t matter what interface you use, just pick one that you’re connected to. Now, look through your packet capture and see if you can distinguish between all the different types that appear.
Let me know what you think. Send me a comment below or email us at [email protected]. And be sure to check out our sister show, Hak5 for more great stuff just like this. I’ll be there, reminding you to trust your technolust.
Great explanations Shannon
Thanks again for the article.Really thank you! Great.
I don’t know whether it’s just me or if everyone else experiencing issues with your website.
It appears as though some of the text within your
content are running off the screen. Can somebody else please comment and let me know if this is happening to them
as well? This may be a problem with my browser
because I’ve had this happen before. Many thanks
Heya i’m for the first time here. I found this board and I find It really
useful & it helped me out a lot. I hope to give something back and help others like you
helped me.
Personal long lasting loans are for sale for every sort
of borrower Gift For Lawyer this securitization implies that in case you fail to
repay the borrowed funds back promptly, you’ll run the risk
of loosing the protection, that is to express your real estate property property.
Excellent blog here! Additionally your web site loads up fast!
What host are you the use of? Can I am getting your associate hyperlink
in your host? I wish my web site loaded up as fast as
yours lol
You also needs to try to pay for up the money you owe and bills punctually Ruth Red by choosing to visit online for yourautomobile loanneeds, you’re accountable with the finance process.
Fast Cash Advance Loans – Genuine Finance within an Instant Fast cash advance loans could be acquired within an instant and that too without
facing too many hassles gold michael kors watch mens expect to supply financial statement, that
will ought to be signed off by way of a cpa.
” It was hard to resist getting another cash advance Imelda Presswood i live off of my college saving from my parents and educational funding.
We have put instruction in the attachments on how to use that trick.