Wireshark User's Guide 20350 for Wireshark 0.99.5
Total Page:16
File Type:pdf, Size:1020Kb
Wireshark User's Guide 20350 for Wireshark 0.99.5 Ulf Lamping, Richard Sharpe, NS Computer Software and Services P/L Ed Warnicke, Wireshark User's Guide: 20350 for Wireshark 0.99.5 by Ulf Lamping, Richard Sharpe, and Ed Warnicke Copyright © 2004-2007 Ulf Lamping Richard Sharpe Ed Warnicke Permission is granted to copy, distribute and/or modify this document under the terms of the GNU General Public License, Ver- sion 2 or any later version published by the Free Software Foundation. All logos and trademarks in this document are property of their respective owner. Table of Contents Preface ................................................................................................................... viii 1. Foreword .................................................................................................... viii 2. Who should read this document? ....................................................................... ix 3. Acknowledgements .......................................................................................... x 4. About this document ....................................................................................... xi 5. Where to get the latest copy of this document? .................................................... xii 6. Providing feedback about this document ........................................................... xiii 1. Introduction ............................................................................................................ 1 1.1. What is Wireshark? ....................................................................................... 1 1.1.1. Some intended purposes ....................................................................... 1 1.1.2. Features ............................................................................................ 1 1.1.3. Live capture from many different network media ...................................... 2 1.1.4. Import files from many other capture programs ........................................ 2 1.1.5. Export files for many other capture programs ........................................... 2 1.1.6. Many protocol decoders ....................................................................... 3 1.1.7. Open Source Software ......................................................................... 3 1.1.8. What Wireshark is not ......................................................................... 3 1.2. System Requirements ..................................................................................... 4 1.2.1. General Remarks ................................................................................ 4 1.2.2. Microsoft Windows ............................................................................. 4 1.2.3. Unix / Linux ...................................................................................... 5 1.3. Where to get Wireshark? ................................................................................ 6 1.4. A brief history of Wireshark ............................................................................ 7 1.5. Development and maintenance of Wireshark ...................................................... 8 1.6. Reporting problems and getting help ................................................................. 9 1.6.1. Website ............................................................................................ 9 1.6.2. Wiki .................................................................................................9 1.6.3. FAQ .................................................................................................9 1.6.4. Mailing Lists ..................................................................................... 9 1.6.5. Reporting Problems ........................................................................... 10 1.6.6. Reporting Crashes on UNIX/Linux platforms ......................................... 10 1.6.7. Reporting Crashes on Windows platforms ............................................. 11 2. Building and Installing Wireshark ............................................................................. 13 2.1. Introduction ............................................................................................... 13 2.2. Obtaining the source and binary distributions .................................................... 14 2.3. Before you build Wireshark under UNIX ......................................................... 15 2.4. Building Wireshark from source under UNIX ................................................... 18 2.5. Installing the binaries under UNIX ................................................................. 20 2.5.1. Installing from rpm's under RedHat and alike ......................................... 20 2.5.2. Installing from deb's under Debian ....................................................... 20 2.5.3. Installing from portage under Gentoo Linux ........................................... 20 2.5.4. Installing from packages under FreeBSD ............................................... 20 2.6. Troubleshooting during the install on Unix ....................................................... 21 2.7. Building from source under Windows ............................................................. 22 2.8. Installing Wireshark under Windows .............................................................. 23 2.8.1. Install Wireshark .............................................................................. 23 2.8.2. Install WinPcap ................................................................................ 25 2.8.3. Update Wireshark ............................................................................. 25 2.8.4. Update WinPcap ............................................................................... 25 2.8.5. Uninstall Wireshark .......................................................................... 26 2.8.6. Uninstall WinPcap ............................................................................ 26 3. User Interface ....................................................................................................... 28 3.1. Introduction ............................................................................................... 28 iv Wireshark User's Guide 3.2. Start Wireshark ........................................................................................... 29 3.3. The Main window ....................................................................................... 30 3.3.1. Main Window Navigation .................................................................. 31 3.4. The Menu .................................................................................................. 32 3.5. The "File" menu .......................................................................................... 34 3.6. The "Edit" menu ......................................................................................... 37 3.7. The "View" menu ........................................................................................ 39 3.8. The "Go" menu ........................................................................................... 43 3.9. The "Capture" menu .................................................................................... 45 3.10. The "Analyze" menu .................................................................................. 47 3.11. The "Statistics" menu ................................................................................. 49 3.12. The "Help" menu ....................................................................................... 52 3.13. The "Main" toolbar .................................................................................... 54 3.14. The "Filter" toolbar .................................................................................... 57 3.15. The "Packet List" pane ............................................................................... 59 3.16. The "Packet Details" pane ........................................................................... 60 3.17. The "Packet Bytes" pane ............................................................................. 61 3.18. The Statusbar ............................................................................................ 62 4. Capturing Live Network Data .................................................................................. 64 4.1. Introduction ............................................................................................... 64 4.2. Prerequisites ............................................................................................... 65 4.3. Start Capturing ........................................................................................... 66 4.4. The "Capture Interfaces" dialog box ................................................................ 67 4.5. The "Capture Options" dialog box .................................................................. 69 4.5.1. Capture frame .................................................................................. 70 4.5.2. Capture File(s) frame ......................................................................... 71 4.5.3. Stop Capture... frame ......................................................................... 71 4.5.4. Display Options frame ....................................................................... 72 4.5.5. Name Resolution frame ..................................................................... 72 4.5.6. Buttons ..........................................................................................