Wireshark Instructions: Difference between revisions
(38 intermediate revisions by the same user not shown) | |||
Line 1: | Line 1: | ||
'''Wireshark Instructions''' This is a walk through to help new students learn how to install and run wireshark for future lab assignments. We will be doing all of this through your Virtual Machine as though you were in the lab during class. If needed the same steps will apply to your home computer with the exception of using a your specific network | '''Wireshark Instructions''' This is a walk through to help new students learn how to install and run wireshark for future lab assignments. We will be doing all of this through your Virtual Machine as though you were in the lab during class. If needed the same steps will apply to your home computer with the exception of using a your specific network adapter. | ||
==Downloading & Installing Wireshark== | ==Downloading & Installing Wireshark== | ||
Line 5: | Line 5: | ||
*Step 1 | *Step 1 | ||
First go to the following link [http://www.wireshark.org/download.html Wireshark Download] | First go to the following link | ||
*'''NOTE''': Make sure to hold control to open the link in a new tab. [http://www.wireshark.org/download.html Wireshark Download] | |||
*Step 2 | *Step 2 | ||
Click on the Windows Installer (32-bit) | Click on the Windows Installer (32-bit). | ||
[[File:Wireshark.2.jpg | |||
[[File:Wireshark.2.jpg|800px]] | |||
*Step 3 | *Step 3 | ||
Click the Save button | Click the Save button. | ||
[[File:Wireshark.3.jpg | |||
[[File:Wireshark.3.jpg|800px]] | |||
*Step 4 | *Step 4 | ||
Click the Run button after the file has been downloaded | Click the Run button after the file has been downloaded. | ||
[[File:Wireshark.4.jpg | |||
[[File:Wireshark.4.jpg|800px]] | |||
*Step 5 | *Step 5 | ||
If an older version is installed replace it by clicking the Yes button | If an older version is installed replace it by clicking the Yes button. | ||
[[File:Wireshark.6.jpg | |||
[[File:Wireshark.6.jpg|800px]] | |||
*Step 6 | *Step 6 | ||
Click the Next button | Click the Next button until you arrive at the Finish button. | ||
[[File:Wireshark.8.jpg | |||
[[File:Wireshark.8.jpg|800px]] | |||
*Step 7 | *Step 7 | ||
Click the Finish button | Click the Finish button. | ||
[[File:Wireshark.10.jpg | |||
[[File:Wireshark.10.jpg|800px]] | |||
*Step 8 | *Step 8 | ||
Click the I Agree button to start the install | Click the I Agree button to start the install. | ||
[[File:Wireshark.12.jpg | |||
[[File:Wireshark.12.jpg|800px]] | |||
*Step 9 | *Step 9 | ||
Click the Next button | Click the Next button until you arrive at the Install WinPcap. | ||
[[File:Wireshark.13.jpg | |||
[[File:Wireshark.13.jpg|800px]] | |||
*Step 10 | *Step 10 | ||
Click the Install button | Click the Install button. | ||
[[File:Wireshark.16.jpg | |||
[[File:Wireshark.16.jpg|800px]] | |||
*Step 11 | *Step 11 | ||
Click the Next button | Click the Next button until you get to WinPcap License Agreement. | ||
[[File:Wireshark.17.jpg | |||
[[File:Wireshark.17.jpg|800px]] | |||
*Step 12 | *Step 12 | ||
Click the I Agree button | Click the I Agree button. | ||
[[File:Wireshark.19.jpg | |||
[[File:Wireshark.19.jpg|800px]] | |||
*Step 13 | *Step 13 | ||
Click the Install button | Click the Install button. | ||
[[File:Wireshark.20.jpg | |||
[[File:Wireshark.20.jpg|800px]] | |||
*Step 14 | *Step 14 | ||
When installation is complete click the Next button | When installation is complete click the Next button. | ||
[[File:Wireshark.27.jpg | |||
[[File:Wireshark.27.jpg|800px]] | |||
*Step 15 | *Step 15 | ||
Click the Finish button | Click the Finish button. | ||
[[File:Wireshark.28.jpg | |||
[[File:Wireshark.28.jpg|800px]] | |||
==Basic Operation of Wireshark== | ==Basic Operation of Wireshark== | ||
Line 55: | Line 139: | ||
*Step 1 | *Step 1 | ||
First open Wireshark by double clicking on the icon. | First open Wireshark by double clicking on the icon. | ||
[[File:Wireshark.29.jpg|800px]] | |||
*Step 2 | *Step 2 | ||
Click on the Capture Options on the left side of the window. | Click on the Capture Options on the left side of the window, will give you a screen that looks like this. | ||
[[File:Wireshark.30.jpg|800px]] | |||
*Step 3 | *Step 3 | ||
Click on the drop arrow button on the top right of the window and select the VMware network adapter. | Click on the drop arrow button on the top right of the window and select the VMware network adapter. | ||
[[File:Wireshark.31.jpg|800px]] | |||
*Step 4 | *Step 4 | ||
Click on the Start button. | Click on the Start button. You are now capturing packets!!! | ||
[[File:Wireshark.32.jpg|800px]] | |||
*Step 5 | *Step 5 | ||
To stop a capture click on the red x button on the top left side on the capture window. | To stop a capture click on the red x button on the top left side on the capture window. | ||
[[File:Wireshark.33.jpg|800px]] | |||
==Examining Capture Data== | ==Examining Capture Data== | ||
In this section we will be showing you how to capture protocols and where to locate the important values given by the use of wireshark. | In this section we will be showing you how to capture protocols and where to locate the important values given by the use of wireshark. | ||
===Color Code=== | |||
*YELLOW: Indicates the MAC Address of both the destination and source. | *YELLOW: Indicates the MAC Address of both the destination and source. | ||
*GREEN: Indicates the NIC Manufacturer of both the destination and source. | *GREEN: Indicates the NIC Manufacturer of both the destination and source. | ||
Line 75: | Line 191: | ||
*BLUE: Indicates the Frame Type of the packet. | *BLUE: Indicates the Frame Type of the packet. | ||
*PINK: Indicates the IPv4 of both the destination and source. | *PINK: Indicates the IPv4 of both the destination and source. | ||
*'''NOTE''': The the | *'''NOTE''': The the '''Preamble''' and the '''FCS''' are '''NOT''' shown on wireshark. | ||
===FTP=== | ===FTP=== | ||
[[File:Wireshark.ftp..jpg|800px]] | |||
===HTTP=== | ===HTTP=== | ||
[[File:Wireshark.http.jpg|800px]] | |||
===ARP=== | ===ARP=== | ||
[[File:Wireshark.arp.jpg|800px]] | |||
===DNS=== | ===DNS=== | ||
[[File:Wireshark.dns.jpg|800px]] | |||
===ICMP=== | ===ICMP=== | ||
[[File:Wireshark.icmp.JPG|800px]] | |||
==Creating a Shortcut to Auto Run Wireshark== | |||
In this section we will be showing you how to create a new desktop icon to auto start your wireshark and have it select the correct network adapter and start capturing by simply double clicking the new icon. | |||
*Step 1 | |||
Right click the Wireshark icon and click copy. | |||
[[File:Wireshark.copy.JPG|800px]] | |||
*Step 2 | |||
Right click on the desktop and click paste. | |||
*Step 3 | |||
Right click the new icon and rename "Wireshark Auto Start" | |||
[[File:Wireshark.new.JPG|800px]] | |||
*Step 4 | |||
Open Wireshark and click on the Capture Options go to the pull down as previously mentioned and select the VMware network adapter, open the window fully to see the path and select everything after the after the : you should have this selected '''\Device\NPF_{numbers}''' as seen in the picture. | |||
[[File:Wireshark.loctarget.JPG|800px]] | |||
*Step 5 | |||
Right click and click properties on the NEW Wireshark icon, and add this to the end of the target line -k -i | |||
*'''NOTE''': You need to have a space before the -k and after the -i. | |||
[[File:Wireshark.shortcutcmd.JPG|800px]] | |||
*Step 6 | |||
Now after the -i "and the space" paste the \Device\NPF_[numbers} to the target line as shown in the picture. | |||
[[File:Wireshark.paste.JPG|800px]] | |||
*Step 7 | |||
Click on the Ok button and now you can simply double click the new icon to start Wireshark and select your network adapter and begin capture with one click of the button. Enjoy!!! | |||
==External links== | ==External links== | ||
*[ | *[[VMWare Setup]] | ||
*[http://www.wireshark.org/download.html Wireshark Download] | *[http://www.wireshark.org/download.html Wireshark Download] | ||
*[http://media-2.cacetech.com/video/wireshark/custom-shortcuts/ Creating Shortcuts] | *[http://media-2.cacetech.com/video/wireshark/custom-shortcuts/ Creating Shortcuts] |
Latest revision as of 15:13, 16 February 2010
Wireshark Instructions This is a walk through to help new students learn how to install and run wireshark for future lab assignments. We will be doing all of this through your Virtual Machine as though you were in the lab during class. If needed the same steps will apply to your home computer with the exception of using a your specific network adapter.
Downloading & Installing Wireshark
This is a quick overview of how to download and install wireshark on to any windows operating system.
- Step 1
First go to the following link
- NOTE: Make sure to hold control to open the link in a new tab. Wireshark Download
- Step 2
Click on the Windows Installer (32-bit).
- Step 3
Click the Save button.
- Step 4
Click the Run button after the file has been downloaded.
- Step 5
If an older version is installed replace it by clicking the Yes button.
- Step 6
Click the Next button until you arrive at the Finish button.
- Step 7
Click the Finish button.
- Step 8
Click the I Agree button to start the install.
- Step 9
Click the Next button until you arrive at the Install WinPcap.
- Step 10
Click the Install button.
- Step 11
Click the Next button until you get to WinPcap License Agreement.
- Step 12
Click the I Agree button.
- Step 13
Click the Install button.
- Step 14
When installation is complete click the Next button.
- Step 15
Click the Finish button.
Basic Operation of Wireshark
This will cover opening and running Wireshark in a virtual machine to capture packets.
- Step 1
First open Wireshark by double clicking on the icon.
- Step 2
Click on the Capture Options on the left side of the window, will give you a screen that looks like this.
- Step 3
Click on the drop arrow button on the top right of the window and select the VMware network adapter.
- Step 4
Click on the Start button. You are now capturing packets!!!
- Step 5
To stop a capture click on the red x button on the top left side on the capture window.
Examining Capture Data
In this section we will be showing you how to capture protocols and where to locate the important values given by the use of wireshark.
Color Code
- YELLOW: Indicates the MAC Address of both the destination and source.
- GREEN: Indicates the NIC Manufacturer of both the destination and source.
- RED: Indicates the NIC Serial Number of both the destination and source.
- BLUE: Indicates the Frame Type of the packet.
- PINK: Indicates the IPv4 of both the destination and source.
- NOTE: The the Preamble and the FCS are NOT shown on wireshark.
FTP
HTTP
ARP
DNS
ICMP
Creating a Shortcut to Auto Run Wireshark
In this section we will be showing you how to create a new desktop icon to auto start your wireshark and have it select the correct network adapter and start capturing by simply double clicking the new icon.
- Step 1
Right click the Wireshark icon and click copy.
- Step 2
Right click on the desktop and click paste.
- Step 3
Right click the new icon and rename "Wireshark Auto Start"
- Step 4
Open Wireshark and click on the Capture Options go to the pull down as previously mentioned and select the VMware network adapter, open the window fully to see the path and select everything after the after the : you should have this selected \Device\NPF_{numbers} as seen in the picture.
- Step 5
Right click and click properties on the NEW Wireshark icon, and add this to the end of the target line -k -i
- NOTE: You need to have a space before the -k and after the -i.
- Step 6
Now after the -i "and the space" paste the \Device\NPF_[numbers} to the target line as shown in the picture.
- Step 7
Click on the Ok button and now you can simply double click the new icon to start Wireshark and select your network adapter and begin capture with one click of the button. Enjoy!!!