skip to content

Wireshark

Wireshark decodes captured traffic layer by layer, filters it by protocol field and rebuilds whole conversations from packets. Interviewers probe it as the answer to what actually crossed the wire.

on this pageshow

explore

questions

page 2 of 2

How does a Wireshark display-filter slice such as `eth.src[0:3] == 00:00:83` work, and how do the `[i:j]` and `[i-j]` forms differ?

level: middleimportance: nice to knowfreq 6%

basics

~20 s

A slice selects part of a byte field, string field or protocol by zero-based offset: [i:j] is j units from i, [i-j] is offsets i to j inclusive. eth.src[0:3] is the source MAC's vendor prefix.

open as a page

On a headless host, how do you get Wireshark's Conversations, Protocol Hierarchy and Expert Info summaries from tshark 4.6, and why doesn't -Y narrow them?

level: middleimportance: nice to knowfreq 9%

basics

~10 s

Use tshark -r file -q with one -z per summary: conv,tcp, endpoints,ip, io,phs, expert. Each -z table ignores the main -Y display filter and takes its own optional filter argument, such as -z conv,tcp,ip.addr==192.0.2.10.

open as a page

In Wireshark 4.6, what does disabling a protocol in Analyze > Enabled Protocols change, and when is it the right tool rather than Decode As?

level: middleimportance: nice to knowfreq 8%

basics

~20 s

Disabling a protocol stops Wireshark calling its dissector and its heuristics anywhere, so that layer and the layers it would have decoded disappear. Use it when a dissector misclaims or misbehaves across many ports; use Decode As to retarget one port.

open as a page

How does editcap's --inject-secrets option produce a self-decrypting TLS capture for a colleague, and what does the file then carry?

level: middleimportance: nice to knowfreq 6%

basics

~20 s

editcap --inject-secrets tls,keys.log in.pcapng out.pcapng copies the key log into a Decryption Secrets Block, so Wireshark decrypts without the key-log preference. The file now carries every secret in that log, and classic pcap cannot hold one.

open as a page

A dumpcap capture must run for days on two busy interfaces and keep only one service's traffic; how do you set the capture filter, and what do you give up?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

Give dumpcap one quoted -f before the first -i so it becomes the default for both interfaces, check it with -d, and accept that excluded traffic, such as ICMP errors or DNS lookups about that service, is gone for good.

open as a page

For an in-house binary protocol on TCP port 9410, what does a minimal Wireshark 4.6 Lua dissector need, and how do you load it?

level: seniorimportance: nice to knowfreq 6%

basics

~20 s

A Proto object, ProtoField definitions assigned to its fields table, a dissector function that adds them to the tree, and DissectorTable.get("tcp.port"):add(9410, proto). The .lua file goes in the personal plugins folder and loads at startup.

open as a page

showing 31–36 of 36