Wireshark Instructions: Difference between revisions

From ITCwiki
Jump to navigation Jump to search
Line 9: Line 9:
*Step 2
*Step 2
Click on the Windows Installer (32-bit)
Click on the Windows Installer (32-bit)
[[File:Wireshark.1.jpg|thumb|800px|left]]
[[File:Wireshark.2.jpg|thumb|800px|left]]
*Step 3
*Step 3
Click the Save button
Click the Save button
 
[[File:Wireshark.3.jpg|thumb|800px|left]]
*Step 4
*Step 4
Click the Run button after the file has been downloaded
Click the Run button after the file has been downloaded
 
[[File:Wireshark.4.jpg|thumb|800px|left]]
*Step 5
*Step 5
If an older version is installed replace it by clicking the Yes button
If an older version is installed replace it by clicking the Yes button
 
[[File:Wireshark.5.jpg|thumb|800px|left]]
*Step 6
*Step 6
Click the Next button untill you arrive at the Finish button
Click the Next button untill you arrive at the Finish button
 
[[File:Wireshark.6.jpg|thumb|800px|left]]
*Step 7
*Step 7
Click the Finish button
Click the Finish button
 
[[File:Wireshark.7.jpg|thumb|800px|left]]
*Step 8
*Step 8
Click the I Agree button to start the install
Click the I Agree button to start the install
 
[[File:Wireshark.8.jpg|thumb|800px|left]]
*Step 9
*Step 9
Click the Next button untill you arrive at the Install WinPcap
Click the Next button untill you arrive at the Install WinPcap
 
[[File:Wireshark.9.jpg|thumb|800px|left]]
*Step 10
*Step 10
Click the Install button
Click the Install button
 
[[File:Wireshark.10.jpg|thumb|800px|left]]
*Step 11
*Step 11
Click the Next button untill you get to WinPcap License Agreement
Click the Next button untill you get to WinPcap License Agreement
 
[[File:Wireshark.11.jpg|thumb|800px|left]]
*Step 12
*Step 12
Click the I Agree button
Click the I Agree button
 
[[File:Wireshark.12.jpg|thumb|800px|left]]
*Step 13
*Step 13
Click the Install button
Click the Install button
 
[[File:Wireshark.13.jpg|thumb|800px|left]]
*Step 14
*Step 14
When installation is complete click the Next button
When installation is complete click the Next button
 
[[File:Wireshark.14.jpg|thumb|800px|left]]
*Step 15
*Step 15
Click the Finish button
Click the Finish button
[[File:Wireshark.15.jpg|thumb|800px|left]]


==Basic Operation of Wireshark==
==Basic Operation of Wireshark==

Revision as of 21:16, 11 February 2010

Wireshark Instructions This is a walk through to help new students learn how to install and run wireshark for future lab assignments. We will be doing all of this through your Virtual Machine as though you were in the lab during class. If needed the same steps will apply to your home computer with the exception of using a your specific network adaptor.

Downloading & Installing Wireshark

This is a quick overview of how to download and install wireshark on to any windows operating system.

  • Step 1

First go to the following link Wireshark Download

  • Step 2

Click on the Windows Installer (32-bit)

Wireshark.2.jpg
  • Step 3

Click the Save button

Wireshark.3.jpg
  • Step 4

Click the Run button after the file has been downloaded

Wireshark.4.jpg
  • Step 5

If an older version is installed replace it by clicking the Yes button

Wireshark.5.jpg
  • Step 6

Click the Next button untill you arrive at the Finish button

Wireshark.6.jpg
  • Step 7

Click the Finish button

Wireshark.7.jpg
  • Step 8

Click the I Agree button to start the install

Wireshark.8.jpg
  • Step 9

Click the Next button untill you arrive at the Install WinPcap

Wireshark.9.jpg
  • Step 10

Click the Install button

Wireshark.10.jpg
  • Step 11

Click the Next button untill you get to WinPcap License Agreement

Wireshark.11.jpg
  • Step 12

Click the I Agree button

Wireshark.12.jpg
  • Step 13

Click the Install button

Wireshark.13.jpg
  • Step 14

When installation is complete click the Next button

Wireshark.14.jpg
  • Step 15

Click the Finish button

Wireshark.15.jpg

Basic Operation of Wireshark

This will cover opening and running Wireshark in a virtual machine to capture packets.

  • Step 1

First open Wireshark by double clicking on the icon.

  • Step 2

Click on the Capture Options on the left side of the window.

  • Step 3

Click on the drop arrow button on the top right of the window and select the VMware network adapter.

  • Step 4

Click on the Start button.

  • Step 5

To stop a capture click on the red x button on the top left side on the capture window.

Examining Capture Data

In this section we will be showing you how to capture protocols and where to locate the important values given by the use of wireshark.

  • YELLOW: Indicates the MAC Address of both the destination and source.
  • GREEN: Indicates the NIC Manufacturer of both the destination and source.
  • RED: Indicates the NIC Serial Number of both the destination and source.
  • BLUE: Indicates the Frame Type of the packet.
  • PINK: Indicates the IPv4 of both the destination and source.
  • NOTE: The the preamble and the FCS are not shown on wireshark.

FTP

HTTP

ARP

DNS

ICMP

External links