Wireshark User's Guide 27488 for Wireshark 1.0.0
Total Page:16
File Type:pdf, Size:1020Kb
Wireshark User's Guide 27488 for Wireshark 1.0.0 Ulf Lamping, Richard Sharpe, NS Computer Software and Services P/L Ed Warnicke, Wireshark User's Guide: 27488 for Wireshark 1.0.0 by Ulf Lamping, Richard Sharpe, and Ed Warnicke Copyright © 2004-2008 Ulf Lamping Richard Sharpe Ed Warnicke Permission is granted to copy, distribute and/or modify this document under the terms of the GNU General Public License, Version 2 or any later version published by the Free Software Foundation. All logos and trademarks in this document are property of their respective owner. Table of Contents Preface ............................................................................................................... ix 1. Foreword ................................................................................................ ix 2. Who should read this document? .................................................................. x 3. Acknowledgements ................................................................................... xi 4. About this document ................................................................................ xii 5. Where to get the latest copy of this document? ............................................. xiii 6. Providing feedback about this document ......................................................xiv 1. Introduction ...................................................................................................... 1 1.1. What is Wireshark? ................................................................................. 1 1.1.1. Some intended purposes ................................................................. 1 1.1.2. Features ...................................................................................... 1 1.1.3. Live capture from many different network media ................................ 2 1.1.4. Import files from many other capture programs .................................. 2 1.1.5. Export files for many other capture programs ..................................... 2 1.1.6. Many protocol decoders ................................................................. 2 1.1.7. Open Source Software ................................................................... 2 1.1.8. What Wireshark is not ................................................................... 3 1.2. System Requirements ............................................................................... 4 1.2.1. General Remarks .......................................................................... 4 1.2.2. Microsoft Windows ....................................................................... 4 1.2.3. Unix / Linux ................................................................................ 5 1.3. Where to get Wireshark? .......................................................................... 6 1.4. A brief history of Wireshark ...................................................................... 7 1.5. Development and maintenance of Wireshark ................................................ 8 1.6. Reporting problems and getting help ........................................................... 9 1.6.1. Website ...................................................................................... 9 1.6.2. Wiki ........................................................................................... 9 1.6.3. FAQ ........................................................................................... 9 1.6.4. Mailing Lists ............................................................................... 9 1.6.5. Reporting Problems ......................................................................10 1.6.6. Reporting Crashes on UNIX/Linux platforms ....................................10 1.6.7. Reporting Crashes on Windows platforms ........................................11 2. Building and Installing Wireshark ........................................................................13 2.1. Introduction ..........................................................................................13 2.2. Obtaining the source and binary distributions ...............................................14 2.3. Before you build Wireshark under UNIX ....................................................15 2.4. Building Wireshark from source under UNIX ..............................................17 2.5. Installing the binaries under UNIX ............................................................18 2.5.1. Installing from rpm's under Red Hat and alike ...................................18 2.5.2. Installing from deb's under Debian ..................................................18 2.5.3. Installing from portage under Gentoo Linux ......................................18 2.5.4. Installing from packages under FreeBSD ..........................................18 2.6. Troubleshooting during the install on Unix ..................................................19 2.7. Building from source under Windows ........................................................20 2.8. Installing Wireshark under Windows .........................................................21 2.8.1. Install Wireshark .........................................................................21 2.8.2. Manual WinPcap Installation .........................................................23 2.8.3. Update Wireshark ........................................................................23 2.8.4. Update WinPcap ..........................................................................23 2.8.5. Uninstall Wireshark .....................................................................23 2.8.6. Uninstall WinPcap .......................................................................24 3. User Interface ..................................................................................................26 3.1. Introduction ..........................................................................................26 3.2. Start Wireshark ......................................................................................27 3.3. The Main window ..................................................................................28 3.3.1. Main Window Navigation .............................................................29 3.4. The Menu .............................................................................................30 iv Wireshark User's Guide 3.5. The "File" menu .....................................................................................31 3.6. The "Edit" menu ....................................................................................34 3.7. The "View" menu ...................................................................................36 3.8. The "Go" menu ......................................................................................40 3.9. The "Capture" menu ...............................................................................42 3.10. The "Analyze" menu .............................................................................44 3.11. The "Statistics" menu ............................................................................46 3.12. The "Tools" menu .................................................................................49 3.13. The "Help" menu ..................................................................................50 3.14. The "Main" toolbar ...............................................................................52 3.15. The "Filter" toolbar ...............................................................................55 3.16. The "Packet List" pane ..........................................................................56 3.17. The "Packet Details" pane ......................................................................57 3.18. The "Packet Bytes" pane ........................................................................58 3.19. The Statusbar .......................................................................................59 4. Capturing Live Network Data .............................................................................62 4.1. Introduction ..........................................................................................62 4.2. Prerequisites ..........................................................................................63 4.3. Start Capturing ......................................................................................64 4.4. The "Capture Interfaces" dialog box ...........................................................65 4.5. The "Capture Options" dialog box .............................................................67 4.5.1. Capture frame .............................................................................67 4.5.2. Capture File(s) frame ....................................................................69 4.5.3. Stop Capture... frame ....................................................................69 4.5.4. Display Options frame ..................................................................70 4.5.5. Name Resolution frame ................................................................70 4.5.6. Buttons ......................................................................................70 4.6. The "Interface Details" dialog box .............................................................71 4.7. Capture files and file modes .....................................................................72 4.8. Link-layer header type ............................................................................74 4.9. Filtering while