AIM: Wireshark

Theory:

Wireshark-win64-3.4.3)

Wireshark is a network packet analyzer. A network packet analyzer presents captured packet data in as much detail as possible.

You could think of a network packet analyzer as a measuring device for examining what’s happening inside a network cable, just like an electrician uses a voltmeter for examining what’s happening inside an electric cable (but at a higher level, of course).

Here are some reasons people use Wireshark:

Network administrators use it to troubleshoot network problems Network security engineers use it to examine security problems QA engineers use it to verify network applications

Developers use it to debug protocol implementations

People use it to learn network protocol internals

i) packet capture using click capture:

wiresharkClick the red “Stop” button near the top left corner of the window when you want to stop capturing trafficwireshark

ii) starting wire shark

After downloading and installing Wireshark, you can launch it and double-click the name of a network interface under Capture to start capturing packets on that interface(wifi or Ethernet or LAN)wireshark

iii) Viewing captired Traffic

View > Coloring Rules.wireshark

You can also save your own captures in Wireshark and open them later. Click File > Save to save your captured packets.wireshark

iv) Analysis and Statistics and Filterswireshark

Apply a filter by typing it into the filter box at the top of the window and clicking Apply (or pressing Enter). For example, type “dns” and you’ll see only DNS packets. When you start typing, Wireshark will help you autocomplete your filter.                      To analyze traffic,

click Analyze > Display Filters to choose a filter from among the default filters included inWireshark.wireshark

v) To find Statistics:

Goto to statistics and select Protocol(DHCP, UDP Multicast)wireshark