Top Banner
Wireshark User's Guide 27848 for Wireshark 1.0.0 Ulf Lamping, Richard Sharpe, NS Computer Software and Services P/L Ed Warnicke,
303

Wireshark User's Guide - eia.pg.edu.pl · PDF fileWireshark User's Guide 27848 for Wireshark 1.0.0 Ulf Lamping, Richard Sharpe, NS Computer Software and Services P/L Ed Warnicke,

Feb 06, 2018

Download

Documents

ngocong
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
  • Wireshark User's Guide

    27848 for Wireshark 1.0.0

    Ulf Lamping,Richard Sharpe, NS Computer Software and Services P/L

    Ed Warnicke,

  • Wireshark User's Guide: 27848

    for Wireshark 1.0.0by Ulf Lamping, Richard Sharpe, and Ed WarnickeCopyright 2004-2008 Ulf Lamping Richard Sharpe Ed Warnicke

    Permission is granted to copy, distribute and/or modify this document under the terms of the GNU General Public License, Ver-sion 2 or any later version published by the Free Software Foundation.

    All logos and trademarks in this document are property of their respective owner.

  • Table of ContentsPreface ..................................................................................................................... ix

    1. Foreword ...................................................................................................... ix2. Who should read this document? ........................................................................ x3. Acknowledgements ......................................................................................... xi4. About this document ...................................................................................... xii5. Where to get the latest copy of this document? ................................................... xiii6. Providing feedback about this document ........................................................... xiv

    1. Introduction ............................................................................................................ 11.1. What is Wireshark? ....................................................................................... 1

    1.1.1. Some intended purposes ....................................................................... 11.1.2. Features ............................................................................................ 11.1.3. Live capture from many different network media ...................................... 21.1.4. Import files from many other capture programs ........................................ 21.1.5. Export files for many other capture programs ........................................... 21.1.6. Many protocol decoders ....................................................................... 31.1.7. Open Source Software ......................................................................... 31.1.8. What Wireshark is not ......................................................................... 3

    1.2. System Requirements ..................................................................................... 41.2.1. General Remarks ................................................................................ 41.2.2. Microsoft Windows ............................................................................. 41.2.3. Unix / Linux ...................................................................................... 5

    1.3. Where to get Wireshark? ................................................................................ 61.4. A brief history of Wireshark ............................................................................ 71.5. Development and maintenance of Wireshark ...................................................... 81.6. Reporting problems and getting help ................................................................. 9

    1.6.1. Website ............................................................................................ 91.6.2. Wiki ................................................................................................. 91.6.3. FAQ ................................................................................................. 91.6.4. Mailing Lists ..................................................................................... 91.6.5. Reporting Problems ........................................................................... 101.6.6. Reporting Crashes on UNIX/Linux platforms ......................................... 101.6.7. Reporting Crashes on Windows platforms ............................................. 11

    2. Building and Installing Wireshark ............................................................................. 132.1. Introduction ............................................................................................... 132.2. Obtaining the source and binary distributions .................................................... 142.3. Before you build Wireshark under UNIX ......................................................... 152.4. Building Wireshark from source under UNIX ................................................... 182.5. Installing the binaries under UNIX ................................................................. 20

    2.5.1. Installing from rpm's under Red Hat and alike ........................................ 202.5.2. Installing from deb's under Debian ....................................................... 202.5.3. Installing from portage under Gentoo Linux ........................................... 202.5.4. Installing from packages under FreeBSD ............................................... 20

    2.6. Troubleshooting during the install on Unix ....................................................... 212.7. Building from source under Windows ............................................................. 222.8. Installing Wireshark under Windows .............................................................. 23

    2.8.1. Install Wireshark .............................................................................. 232.8.2. Manual WinPcap Installation .............................................................. 252.8.3. Update Wireshark ............................................................................. 252.8.4. Update WinPcap ............................................................................... 252.8.5. Uninstall Wireshark .......................................................................... 262.8.6. Uninstall WinPcap ............................................................................ 26

    3. User Interface ....................................................................................................... 283.1. Introduction ............................................................................................... 28

    iv

  • 3.2. Start Wireshark ........................................................................................... 293.3. The Main window ....................................................................................... 30

    3.3.1. Main Window Navigation .................................................................. 313.4. The Menu .................................................................................................. 323.5. The "File" menu .......................................................................................... 343.6. The "Edit" menu ......................................................................................... 373.7. The "View" menu ........................................................................................ 393.8. The "Go" menu ........................................................................................... 443.9. The "Capture" menu .................................................................................... 463.10. The "Analyze" menu .................................................................................. 483.11. The "Statistics" menu ................................................................................. 503.12. The "Tools" menu ...................................................................................... 533.13. The "Help" menu ....................................................................................... 543.14. The "Main" toolbar .................................................................................... 563.15. The "Filter" toolbar .................................................................................... 593.16. The "Packet List" pane ............................................................................... 613.17. The "Packet Details" pane ........................................................................... 623.18. The "Packet Bytes" pane ............................................................................. 633.19. The Statusbar ............................................................................................ 64

    4. Capturing Live Network Data .................................................................................. 674.1. Introduction ............................................................................................... 674.2. Prerequisites ............................................................................................... 684.3. Start Capturing ........................................................................................... 694.4. The "Capture Interfaces" dialog box ................................................................ 704.5. The "Capture Options" dialog box .................................................................. 72

    4.5.1. Capture frame .................................................................................. 734.5.2. Capture File(s) frame ......................................................................... 744.5.3. Stop Capture... frame ......................................................................... 744.5.4. Display Options frame ....................................................................... 754.5.5. Name Resolution frame ..................................................................... 754.5.6. Buttons ........................................................................................... 75

    4.6. The "Interface Details" dialog box .................................................................. 764.7. Capture files and file mode