Wireshark User's Guide 31279 for Wireshark 1.2
Total Page:16
File Type:pdf, Size:1020Kb
Wireshark User's Guide 31279 for Wireshark 1.2 Ulf Lamping, Richard Sharpe, NS Computer Software and Services P/L Ed Warnicke, Wireshark User's Guide: 31279 for Wireshark 1.2 by Ulf Lamping, Richard Sharpe, and Ed Warnicke Copyright © 2004-2008 Ulf Lamping Richard Sharpe Ed Warnicke Permission is granted to copy, distribute and/or modify this document under the terms of the GNU General Public License, Version 2 or any later version published by the Free Software Foundation. All logos and trademarks in this document are property of their respective owner. Table of Contents Preface ............................................................................................................................ ix 1. Foreword .............................................................................................................. ix 2. Who should read this document? .............................................................................. ix 3. Acknowledgements ................................................................................................ ix 4. About this document ............................................................................................... x 5. Where to get the latest copy of this document? ............................................................. x 6. Providing feedback about this document ..................................................................... x 1. Introduction ................................................................................................................... 1 1.1. What is Wireshark? .............................................................................................. 1 1.1.1. Some intended purposes .............................................................................. 1 1.1.2. Features ................................................................................................... 1 1.1.3. Live capture from many different network media ............................................. 2 1.1.4. Import files from many other capture programs ............................................... 2 1.1.5. Export files for many other capture programs .................................................. 2 1.1.6. Many protocol decoders .............................................................................. 2 1.1.7. Open Source Software ................................................................................ 3 1.1.8. What Wireshark is not ................................................................................ 3 1.2. System Requirements ............................................................................................ 3 1.2.1. General Remarks ....................................................................................... 3 1.2.2. Microsoft Windows .................................................................................... 3 1.2.3. Unix / Linux ............................................................................................. 4 1.3. Where to get Wireshark? ....................................................................................... 5 1.4. A brief history of Wireshark .................................................................................. 5 1.5. Development and maintenance of Wireshark ............................................................ 5 1.6. Reporting problems and getting help ........................................................................ 6 1.6.1. Website .................................................................................................... 6 1.6.2. Wiki ........................................................................................................ 6 1.6.3. FAQ ........................................................................................................ 6 1.6.4. Mailing Lists ............................................................................................. 7 1.6.5. Reporting Problems .................................................................................... 7 1.6.6. Reporting Crashes on UNIX/Linux platforms .................................................. 8 1.6.7. Reporting Crashes on Windows platforms ...................................................... 8 2. Building and Installing Wireshark ...................................................................................... 9 2.1. Introduction ......................................................................................................... 9 2.2. Obtaining the source and binary distributions ............................................................ 9 2.3. Before you build Wireshark under UNIX ................................................................ 10 2.4. Building Wireshark from source under UNIX .......................................................... 11 2.5. Installing the binaries under UNIX ......................................................................... 12 2.5.1. Installing from rpm's under Red Hat and alike ............................................... 12 2.5.2. Installing from deb's under Debian .............................................................. 13 2.5.3. Installing from portage under Gentoo Linux .................................................. 13 2.5.4. Installing from packages under FreeBSD ...................................................... 13 2.6. Troubleshooting during the install on Unix .............................................................. 13 2.7. Building from source under Windows ..................................................................... 14 2.8. Installing Wireshark under Windows ...................................................................... 14 2.8.1. Install Wireshark ...................................................................................... 14 2.8.2. Manual WinPcap Installation ...................................................................... 16 2.8.3. Update Wireshark ..................................................................................... 16 2.8.4. Update WinPcap ...................................................................................... 16 2.8.5. Uninstall Wireshark .................................................................................. 17 2.8.6. Uninstall WinPcap .................................................................................... 17 iii Wireshark User's Guide 3. User Interface ............................................................................................................... 18 3.1. Introduction ....................................................................................................... 18 3.2. Start Wireshark .................................................................................................. 18 3.3. The Main window .............................................................................................. 18 3.3.1. Main Window Navigation .......................................................................... 20 3.4. The Menu ......................................................................................................... 20 3.5. The "File" menu ................................................................................................. 21 3.6. The "Edit" menu ................................................................................................. 24 3.7. The "View" menu ............................................................................................... 26 3.8. The "Go" menu .................................................................................................. 28 3.9. The "Capture" menu ............................................................................................ 29 3.10. The "Analyze" menu ......................................................................................... 30 3.11. The "Statistics" menu ......................................................................................... 33 3.12. The "Tools" menu ............................................................................................. 35 3.13. The "Help" menu .............................................................................................. 35 3.14. The "Main" toolbar ........................................................................................... 36 3.15. The "Filter" toolbar ........................................................................................... 38 3.16. The "Packet List" pane ....................................................................................... 38 3.17. The "Packet Details" pane .................................................................................. 39 3.18. The "Packet Bytes" pane .................................................................................... 40 3.19. The Statusbar ................................................................................................... 40 4. Capturing Live Network Data .......................................................................................... 43 4.1. Introduction ....................................................................................................... 43 4.2. Prerequisites ...................................................................................................... 43 4.3. Start Capturing ................................................................................................... 44 4.4. The "Capture Interfaces" dialog box ....................................................................... 44 4.5. The "Capture