How to use Wireshark? Traffic analysis

, . , . , WireShark, .

, WireShark, , . : . Ethernet, IEEE 802.11, PPP . VoIP.

wireshark how to use




GNU GPL, - . Linux, MacOS, Windows.

WireShark?

-, . Linux Ubuntu, .

:

sudo apt-get install wireshark





. . , . :

sudo wireshark

. , 3 . , , — .

Capture . , , eth0 Start .

. . . . , , . , .

. .

.

, . . WireShark .

— Filter. , Expression.





:

  • ip.dst — ip ;
  • ip.src — ;
  • ip.addr — ip;
  • ip.proto — .

WireShark —

, , Filter . , — ip.dst == 172.217.23.131 - "". — , - — ip.dst == 172.217.23.131 || ip.src == 172.217.23.131. , .

, ip.ttl < 10. 10. , — http.content_length > 5000.

WireShark . , Apply as Column. .

wireshark guide




. Apply as Filter.

WireShark , , . , Follow TCP Stream. .

WireShark . Expert Tools. , . — Errors, Warnings . , , , .

, WireShark . Telephony. VoIP .

VoIP Calls Telephony .

, , . WireShark , . HTTP File. , .

wireshark in Russian




, WireShark . .

WireShark . . WireShark .

wireshark instruction in Russian




However, those who have been working in the IT field for a long time will not be particularly difficult to understand the program. A great opportunity and rich functionality will brighten up all the difficulties in learning.

It is worth noting that in some countries, using a sniffer, such as WireShark, may be illegal.




All Articles