Beruflich Dokumente
Kultur Dokumente
Sterbenz
ITTC
Communication Networks Laboratory
malenazi@ittc.ku.edu
jpgs@eecs.ku.edu
http://www.ittc.ku.edu/~jpgs/courses/nets
22 January 2013
rev. 13.0
ITTC
L1.0
L1.1
L1.2
L1.3
L1.4
22 January 2013
NET-L1-2
ITTC
L1.0
L1.1
L1.2
L1.3
L1.4
22 January 2013
NET-L1-3
ITTC
Wireshark labs
Socket programming
Network simulation
22 January 2013
NET-L1-4
ITTC
L1.0
L1.1
L1.2
L1.3
L1.4
22 January 2013
NET-L1-5
ITTC
22 January 2013
NET-L1-6
ITTC
22 January 2013
NET-L1-7
ITTC
L1.0
L1.1
L1.2
L1.3
L1.4
22 January 2013
NET-L1-8
ITTC
Wireshark Installation
Highlights
22 January 2013
NET-L1-9
ITTC
Wireshark Installation
Overview
22 January 2013
NET-L1-10
ITTC
Wireshark Usage
Windows XP Installation1
Go to
wireshark.org
Click on
Download
Wireshark
Save and run
the executable
(.exe) file
Installation
wizard is
intuitive
22 January 2013
NET-L1-11
ITTC
Wireshark Usage
Windows XP Installation2
pcap library is
required to
capture lowlevel network
messages
WinPcap for
Windows,
libpcap for
UNIX/Linux
Latest
WinPcap
release 4.1.2
22 January 2013
NET-L1-12
ITTC
Wireshark Installation
Windows XP Installation3
22 January 2013
NET-L1-13
ITTC
Wireshark Usage
Main Features
22 January 2013
NET-L1-14
ITTC
Wireshark GUI
Main Window
menu
main toolbar
filter toolbar
packet list
pane
packet details
pane
packet bytes
pane
status bar
22 January 2013
NET-L1-15
ITTC
Wireshark Usage
Starting Capture
To capture:
go to Capture
menu and
select
Interfaces
Start
capturing on
interface that
has IP address
Other ways of
capturing
possible
22 January 2013
NET-L1-16
ITTC
Wireshark Usage
Capturing1
Once the
capturing
starts,
until the data
is exchanged
on Network
Interface Card
(NIC),
main window
will be blank
22 January 2013
NET-L1-17
ITTC
Wireshark Usage
Capturing2
When packets
exchanged on
NIC,
the packets
will be
dumped to
main window
22 January 2013
NET-L1-18
ITTC
Wireshark Usage
Stopping Capture
Capturing can
be stopped by
clicking on
Stop the
running
capture
button on the
main toolbar
22 January 2013
NET-L1-19
ITTC
Wireshark Usage
Filtering
Filter by
entering the
protocol
name or field
name and
click the apply
button in the
filter menu
Detailed filters
can be applied
by creating
expressions
22 January 2013
NET-L1-20
ITTC
L1.0
L1.1
L1.2
L1.3
L1.4
22 January 2013
NET-L1-21
ITTC
22 January 2013
NET-L1-22
ITTC
Analysis is
performed
manually
Example
shows TCP
segment with
SYN and ACK
fields set to 1
22 January 2013
NET-L1-23
ITTC
Zoom in or
out is possible
in main
toolbar
Packet Byte
pane consists
of offset, Hex,
and ASCII
fields
22 January 2013
NET-L1-24
ITTC
22 January 2013
NET-L1-25
ITTC
L1.0
L1.1
L1.2
L1.3
L1.4
22 January 2013
NET-L1-26
ITTC
Getting Started
http://http://www.pearsonhighered.com/pearsonhigheredus/educator/product/
products_detail.page?isbn=9780132856201
22 January 2013
NET-L1-27
ITTC
22 January 2013
NET-L1-28