Wireshark
Wireshark decodes captured traffic layer by layer, filters it by protocol field and rebuilds whole conversations from packets. Interviewers probe it as the answer to what actually crossed the wire.
on this pageshowhide
explore
- Capture Interfaces and Setup6 questions
- Capture Filters3 questions
- Display Filters6 questions
- Protocol Dissectors5 questions
- Stream Following and Reassembly5 questions
- Expert Info and Statistics6 questions
- TLS Decryption5 questions
questions
page 2 of 2How does a Wireshark display-filter slice such as `eth.src[0:3] == 00:00:83` work, and how do the `[i:j]` and `[i-j]` forms differ?
basics
~20 sA slice selects part of a byte field, string field or protocol by zero-based offset: [i:j] is j units from i, [i-j] is offsets i to j inclusive. eth.src[0:3] is the source MAC's vendor prefix.
On a headless host, how do you get Wireshark's Conversations, Protocol Hierarchy and Expert Info summaries from tshark 4.6, and why doesn't -Y narrow them?
basics
~10 sUse tshark -r file -q with one -z per summary: conv,tcp, endpoints,ip, io,phs, expert. Each -z table ignores the main -Y display filter and takes its own optional filter argument, such as -z conv,tcp,ip.addr==192.0.2.10.
In Wireshark 4.6, what does disabling a protocol in Analyze > Enabled Protocols change, and when is it the right tool rather than Decode As?
basics
~20 sDisabling a protocol stops Wireshark calling its dissector and its heuristics anywhere, so that layer and the layers it would have decoded disappear. Use it when a dissector misclaims or misbehaves across many ports; use Decode As to retarget one port.
How does editcap's --inject-secrets option produce a self-decrypting TLS capture for a colleague, and what does the file then carry?
basics
~20 seditcap --inject-secrets tls,keys.log in.pcapng out.pcapng copies the key log into a Decryption Secrets Block, so Wireshark decrypts without the key-log preference. The file now carries every secret in that log, and classic pcap cannot hold one.
A dumpcap capture must run for days on two busy interfaces and keep only one service's traffic; how do you set the capture filter, and what do you give up?
basics
~20 sGive dumpcap one quoted -f before the first -i so it becomes the default for both interfaces, check it with -d, and accept that excluded traffic, such as ICMP errors or DNS lookups about that service, is gone for good.
For an in-house binary protocol on TCP port 9410, what does a minimal Wireshark 4.6 Lua dissector need, and how do you load it?
basics
~20 sA Proto object, ProtoField definitions assigned to its fields table, a dissector function that adds them to the tree, and DissectorTable.get("tcp.port"):add(9410, proto). The .lua file goes in the personal plugins folder and loads at startup.
showing 31–36 of 36