for wireshark 1 - it.iitb.ac.in · pdf filethe packet range frame ..... 92 5.10. the packet...

Download for Wireshark 1 - it.iitb.ac.in · PDF fileThe Packet Range frame ..... 92 5.10. The Packet Format frame ... Wireshark's Lua API Reference Manual

If you can't read please download the document

Upload: lephuc

Post on 06-Feb-2018

223 views

Category:

Documents


0 download

TRANSCRIPT

  • Wireshark User's Guide

    for Wireshark 1.11

    Ulf Lamping,Richard Sharpe, NS Computer Software and Services P/L

    Ed Warnicke,

  • Wireshark User's Guide: for Wireshark 1.11

    by Ulf Lamping, Richard Sharpe, and Ed WarnickeCopyright 2004-2013 Ulf Lamping , Richard Sharpe , Ed Warnicke

    Permission is granted to copy, distribute and/or modify this document under the terms of the GNU General Public License, Version 2 or anylater version published by the Free Software Foundation.

    All logos and trademarks in this document are property of their respective owner.

  • iii

    Preface ....................................................................................................................... ix1. Foreword ........................................................................................................ ix2. Who should read this document? ......................................................................... ix3. Acknowledgements ........................................................................................... ix4. About this document .......................................................................................... x5. Where to get the latest copy of this document? ....................................................... x6. Providing feedback about this document ................................................................ x

    1. Introduction .............................................................................................................. 11.1. What is Wireshark? ......................................................................................... 1

    1.1.1. Some intended purposes ........................................................................ 11.1.2. Features .............................................................................................. 11.1.3. Live capture from many different network media ........................................ 21.1.4. Import files from many other capture programs .......................................... 21.1.5. Export files for many other capture programs ............................................ 21.1.6. Many protocol decoders ......................................................................... 21.1.7. Open Source Software ........................................................................... 21.1.8. What Wireshark is not ........................................................................... 3

    1.2. System Requirements ...................................................................................... 31.2.1. General Remarks .................................................................................. 31.2.2. Microsoft Windows .............................................................................. 31.2.3. Unix / Linux ........................................................................................ 4

    1.3. Where to get Wireshark? .................................................................................. 51.4. A brief history of Wireshark ............................................................................. 51.5. Development and maintenance of Wireshark ........................................................ 51.6. Reporting problems and getting help .................................................................. 6

    1.6.1. Website .............................................................................................. 61.6.2. Wiki .................................................................................................. 61.6.3. Q&A Forum ........................................................................................ 61.6.4. FAQ .................................................................................................. 61.6.5. Mailing Lists ....................................................................................... 71.6.6. Reporting Problems .............................................................................. 71.6.7. Reporting Crashes on UNIX/Linux platforms ............................................. 81.6.8. Reporting Crashes on Windows platforms ................................................. 8

    2. Building and Installing Wireshark ................................................................................ 92.1. Introduction ................................................................................................... 92.2. Obtaining the source and binary distributions ....................................................... 92.3. Before you build Wireshark under UNIX ........................................................... 102.4. Building Wireshark from source under UNIX ..................................................... 112.5. Installing the binaries under UNIX ................................................................... 12

    2.5.1. Installing from rpm's under Red Hat and alike .......................................... 122.5.2. Installing from deb's under Debian, Ubuntu and other Debian derivatives ....... 132.5.3. Installing from portage under Gentoo Linux ............................................. 132.5.4. Installing from packages under FreeBSD ................................................. 13

    2.6. Troubleshooting during the install on Unix ........................................................ 132.7. Building from source under Windows ............................................................... 142.8. Installing Wireshark under Windows ................................................................ 14

    2.8.1. Install Wireshark ................................................................................ 142.8.2. Manual WinPcap Installation ................................................................ 162.8.3. Update Wireshark ............................................................................... 162.8.4. Update WinPcap ................................................................................. 162.8.5. Uninstall Wireshark ............................................................................. 162.8.6. Uninstall WinPcap .............................................................................. 17

    3. User Interface ......................................................................................................... 183.1. Introduction .................................................................................................. 183.2. Start Wireshark ............................................................................................. 183.3. The Main window ......................................................................................... 18

    3.3.1. Main Window Navigation .................................................................... 193.4. The Menu .................................................................................................... 20

  • Wireshark User's Guide

    iv

    3.5. The "File" menu ........................................................................................... 213.6. The "Edit" menu ........................................................................................... 243.7. The "View" menu ......................................................................................... 263.8. The "Go" menu ............................................................................................ 293.9. The "Capture" menu ...................................................................................... 313.10. The "Analyze" menu .................................................................................... 323.11. The "Statistics" menu ................................................................................... 333.12. The "Telephony" menu ................................................................................. 353.13. The "Tools" menu ....................................................................................... 373.14. The "Internals" menu ................................................................................... 373.15. The "Help" menu ........................................................................................ 383.16. The "Main" toolbar ...................................................................................... 403.17. The "Filter" toolbar ...................................................................................... 423.18. The "Packet List" pane ................................................................................. 433.19. The "Packet Details" pane ............................................................................. 443.20. The "Packet Bytes" pane ............................................................................... 443.21. The Statusbar .............................................................................................. 45

    4. Capturing Live Network Data .................................................................................... 474.1. Introduction .................................................................................................. 474.2. Prerequisites ................................................................................................. 474.3. Start Capturing ............................................................................................. 474.4. The "Capture Interfaces" dialog box ................................................................. 484.5. The "Capture Options" dialog box .................................................................... 50

    4.5.1. Capture frame .................................................................................... 524.5.2. Capture File(s) frame ........................................................................... 534.5.3. Stop