333 lines
19 KiB
HTML
333 lines
19 KiB
HTML
<!DOCTYPE html>
|
|
|
|
|
|
<html class="no-js" lang="en">
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<title>How I use Wireshark</title>
|
|
<meta name="author" content="Julia Evans">
|
|
<meta name="HandheldFriendly" content="True">
|
|
<meta name="MobileOptimized" content="320">
|
|
<meta name="description" content="How I use Wireshark">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
|
|
|
<meta property="og:title" content='How I use Wireshark'>
|
|
<meta property="og:type" content="website" />
|
|
<meta property="og:url" content="https://jvns.ca/blog/2018/06/19/what-i-use-wireshark-for/" />
|
|
<meta property="og:site_name" content="Julia Evans" />
|
|
|
|
<link rel="canonical" href="https://jvns.ca/blog/2018/06/19/what-i-use-wireshark-for/">
|
|
<link href="/favicon.ico" rel="icon">
|
|
|
|
<link href="/stylesheets/screen.css" rel="preload" type="text/css" as="style">
|
|
|
|
<link href="/stylesheets/screen.css" media="screen, projection" rel="stylesheet" type="text/css">
|
|
<link href="/stylesheets/print.css" media="print" rel="stylesheet" type="text/css">
|
|
|
|
|
|
<link href="/atom.xml" rel="alternate" title="Julia Evans" type="application/atom+xml">
|
|
|
|
|
|
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/katex@0.16.4/dist/katex.min.css" integrity="sha384-vKruj+a13U8yHIkAyGgK1J3ArTLzrFGBbBc0tDp4ad/EyewESeXE/Iv67Aj8gKZ0" crossorigin="anonymous">
|
|
<script defer data-domain="jvns.ca" src="https://plausible.io/js/script.js"></script>
|
|
<script defer src="https://cdn.jsdelivr.net/npm/katex@0.16.4/dist/katex.min.js" integrity="sha384-PwRUT/YqbnEjkZO0zZxNqcxACrXe+j766U2amXcgMg5457rve2Y7I6ZJSm2A0mS4" crossorigin="anonymous"></script>
|
|
<script defer src="https://cdn.jsdelivr.net/npm/katex@0.16.4/dist/contrib/auto-render.min.js" integrity="sha384-+VBxd3r6XgURycqtZ117nYw44OOcIax56Z4dCRWbxyPt0Koah1uHoK0o4+/RRE05" crossorigin="anonymous" onload="renderMathInElement(document.body);"></script>
|
|
|
|
<script defer type="text/javascript">
|
|
window.heap=window.heap||[],heap.load=function(e,t){window.heap.appid=e,window.heap.config=t=t||{};var r=document.createElement("script");r.type="text/javascript",r.async=!0,r.src="https://cdn.heapanalytics.com/js/heap-"+e+".js";var a=document.getElementsByTagName("script")[0];a.parentNode.insertBefore(r,a);for(var n=function(e){return function(){heap.push([e].concat(Array.prototype.slice.call(arguments,0)))}},p=["addEventProperties","addUserProperties","clearEventProperties","identify","resetIdentity","removeEventProperty","setEventProperties","track","unsetEventProperty"],o=0;o<p.length;o++)heap[p[o]]=n(p[o])};
|
|
heap.load("2242143965");
|
|
</script>
|
|
</head>
|
|
<body>
|
|
<div id="skiptocontent">
|
|
<a href="#main">Skip to main content</a>
|
|
</div>
|
|
<div id="wrap">
|
|
<header role="banner">
|
|
<hgroup>
|
|
<h1><a href="/">Julia Evans</a></h1>
|
|
</hgroup>
|
|
<ul class="header-links">
|
|
<li><a href="/about">About</a></li>
|
|
<li><a href="/talks">Talks</a></li>
|
|
<li><a href="/projects/">Projects</a></li>
|
|
<li><a rel="me" href="https://social.jvns.ca/@b0rk">Mastodon</a></li>
|
|
<li><a href="https://bsky.app/profile/b0rk.jvns.ca">Bluesky</a></li>
|
|
<li><a href="https://github.com/jvns">Github</a></li>
|
|
</ul>
|
|
</header>
|
|
<nav role="navigation" class="header-nav"><ul class="main-navigation">
|
|
<li><a href="/categories/favorite/">Favorites</a></li>
|
|
<li><a href="/til/">TIL</a></li>
|
|
<li><a href="https://wizardzines.com">Zines</a></li>
|
|
<li class="subscription" data-subscription="rss"><a href="/atom.xml" rel="subscribe-rss" title="subscribe via RSS">RSS</a></li>
|
|
</ul>
|
|
</nav>
|
|
<div id="main">
|
|
<div id="content">
|
|
|
|
|
|
<div>
|
|
<article class="hentry" role="article">
|
|
<header>
|
|
<h1 class="entry-title">How I use Wireshark</h1>
|
|
|
|
<div class="post-tags">
|
|
|
|
</div>
|
|
<p class="meta sans">
|
|
<time class="date" datetime="2018-06-19T00:28:24" pubdate data-updated="true">
|
|
|
|
June 19, 2018
|
|
|
|
</time>
|
|
</p>
|
|
</header>
|
|
<main>
|
|
<p>Hello! I was using Wireshark to debug a networking problem today, and I realized I’ve never written
|
|
a blog post about Wireshark! Wireshark is one of my very favourite networking tools, so let’s fix
|
|
that :)</p>
|
|
<p>Wireshark is a really powerful and complicated tool, but in practice I only know how to do a very
|
|
small number of things with it, and those things are really useful! So in this blog post, I’ll
|
|
explain the 5 main things I use Wireshark for, and hopefully you’ll have a slightly clearer idea of
|
|
why it’s useful.</p>
|
|
<h3 id="what-s-wireshark" class="post-heading">
|
|
<a href="#what-s-wireshark">
|
|
what’s Wireshark?
|
|
</a>
|
|
</h3>
|
|
<p><a href="https://www.wireshark.org/">Wireshark</a> is a graphical network packet analysis tool.</p>
|
|
<p>On Mac, you can download & install it from their homepage, and on Debian-based distros you can
|
|
install it with <code>sudo apt install wireshark</code>. There’s also an official
|
|
<a href="https://launchpad.net/~wireshark-dev/+archive/ubuntu/stable">wireshark-dev PPA</a> you can use to get
|
|
more up-to-date Wireshark versions.</p>
|
|
<p>Wireshark looks like this, and it can be a little overwhelming at first. There’s a slightly
|
|
mysterious search box, and a lot of packets, and how do you even use this thing?</p>
|
|
<p><a href="https://jvns.ca/images/wireshark_screenshot.png"><img src="https://jvns.ca/images/wireshark_screenshot.png"></a></p>
|
|
<h3 id="use-wireshark-to-analyze-pcap-files" class="post-heading">
|
|
<a href="#use-wireshark-to-analyze-pcap-files">
|
|
Use Wireshark to analyze pcap files
|
|
</a>
|
|
</h3>
|
|
<p>Usually I use Wireshark to debug networking problems in production. My Wireshark workflow
|
|
is:</p>
|
|
<ol>
|
|
<li>Capture packets with tcpdump (typically something like <code>sudo tcpdump port 443 -w output.pcap</code></li>
|
|
<li>scp the pcap file to my laptop (<code>scp host:~/output.pcap .</code>)</li>
|
|
<li>Open the pcap file in Wireshark (<code>wireshark output.pcap</code>)</li>
|
|
</ol>
|
|
<p>That’s pretty simple! But once you have a pcap file with a bunch of packets on your laptop, what do
|
|
you do with it?</p>
|
|
<h3 id="look-at-a-single-tcp-connection" class="post-heading">
|
|
<a href="#look-at-a-single-tcp-connection">
|
|
Look at a single TCP connection
|
|
</a>
|
|
</h3>
|
|
<p>Often when I’m debugging something in Wireshark, what’s happened is that there’s some TCP
|
|
connection, and something went wrong with the connection for some reason. Wireshark
|
|
makes it really easy to look at the lifetime of a TCP connection and see what happened!</p>
|
|
<p>You can do that by right clicking on a packet and clicking “Conversation filter” -> “TCP”.</p>
|
|
<p><a href="https://jvns.ca/images/wireshark_filter.png"><img src="https://jvns.ca/images/wireshark_filter.png"></a></p>
|
|
<p>And then Wireshark will just show you other packets from the same TCP connection as that packet!!
|
|
Here you’ll see a successful SSL connection – there’s are packets that say “client hello”,
|
|
“service hello”, “certificate”, “server key exchange”, which are all part of setting up a SSL
|
|
connection. Neat!</p>
|
|
<p><a href="https://jvns.ca/images/wireshark_tcp.png"><img src="https://jvns.ca/images/wireshark_tcp.png"></a></p>
|
|
<p>I actually used this today to debug an SSL issue – at work today, some connections were being
|
|
reset, and I noticed that after the “client hello” packet was sent, the client was sending a “FIN
|
|
ACK” packet which terminates the TLS connection. This was useful because I could tell that the
|
|
<strong>client</strong> was terminating the connection, not the server! So immediately I knew that the client was
|
|
to blame and I could focus my investigations there.</p>
|
|
<p>This pattern is pretty typical of how I use Wireshark. Usually there’s a client and a server, and
|
|
there’s a bug or configuration error on either the client or the server. Wireshark is invaluable for
|
|
helping me figure out whether I should blame the client or the server :)</p>
|
|
<h3 id="decode-as" class="post-heading">
|
|
<a href="#decode-as">
|
|
“Decode as”
|
|
</a>
|
|
</h3>
|
|
<p>Wireshark uses the port to try to guess what kind of packet every packet is, and often it does a
|
|
good job! If it sees traffic on port 80, it’ll assume it’s HTTP traffic, and it’s usually right.</p>
|
|
<p>But sometimes you have HTTP traffic happening on an unusual port, and you need to give Wireshark
|
|
some hints. If you right click on a packet and click “Decode as”, you can tell Wireshark what
|
|
protocol packets on that port are and then it’ll be much easier to navigate and search.</p>
|
|
<h3 id="see-the-contents-of-a-packet" class="post-heading">
|
|
<a href="#see-the-contents-of-a-packet">
|
|
See the contents of a packet
|
|
</a>
|
|
</h3>
|
|
<p>Wireshark has an AMAZING details view that explains the contents of any packet. Let’s take the
|
|
“client hello” packet from the details above. This packet is the first packet sent during a SSL
|
|
connection – the client is saying “hello! here I am!”.</p>
|
|
<p>Wireshark gives you two super useful tools for investigating the contents of a packet. The first one
|
|
is this view where you can expand every header the packet has (ethernet header! IP header! TCP
|
|
header!) and look at what’s in it:</p>
|
|
<p><a href="https://jvns.ca/images/wireshark_packet_details_list.png"><img src="https://jvns.ca/images/wireshark_packet_details_list.png"></a></p>
|
|
<p>The second view, which is really magical, is this one which shows you the raw bytes of a packet. The
|
|
neat thing about this is that if you hover over one of the bytes with your mouse (like here I’ve
|
|
hovered over <code>tiles.services.mozilla.com</code>), it’ll tell you at the bottom of the screen what field
|
|
those bytes correspond to here (in this case the “Server Name” field) and the Wireshark codename for
|
|
that field (in this case <code>ssl.handshake.extensions_server_name</code>)</p>
|
|
<p><a href="https://jvns.ca/images/wireshark_packet_details.png"><img src="https://jvns.ca/images/wireshark_packet_details.png"></a></p>
|
|
<h3 id="search-for-specific-packets" class="post-heading">
|
|
<a href="#search-for-specific-packets">
|
|
Search for specific packets
|
|
</a>
|
|
</h3>
|
|
<p>Wireshark has a great query language, and you can really easily search for specific packets! I
|
|
usually just use really simple queries with Wireshark. Here are a few examples of the kinds of
|
|
searches I do:</p>
|
|
<ul>
|
|
<li><code>frame contains "mozilla"</code> – search for the string “mozilla” anywhere in the packet</li>
|
|
<li><code>tcp.port == 443</code> – tcp port is 443</li>
|
|
<li><code>dns.resp.len > 0</code> – all DNS responses</li>
|
|
<li><code>ip.addr == 52.7.23.87</code> – source or dest IP address is 52.7.23.87</li>
|
|
</ul>
|
|
<p>Wireshark’s packet search language is much more powerful than tcpdump’s (and it has tab
|
|
completion!!), so I’ll often capture a large amount of packets with tcpdump (“all packets on port
|
|
443”) and then do some more in depth searching using Wireshark.</p>
|
|
<h3 id="see-statistics-on-tcp-connection-duration" class="post-heading">
|
|
<a href="#see-statistics-on-tcp-connection-duration">
|
|
see statistics on TCP connection duration
|
|
</a>
|
|
</h3>
|
|
<p>Sometimes I want to specifically investigate slow TCP connections. But what if I have a packet
|
|
capture file with many thousands of packets?! How do I find the slow TCP connection?</p>
|
|
<p>If you click ‘Statistics’ in the menu then ‘Conversations’, Wireshark will give you this amazing
|
|
statistics view that looks like this:</p>
|
|
<p><a href="https://jvns.ca/images/wireshark_statistics.png"><img src="https://jvns.ca/images/wireshark_statistics.png"></a></p>
|
|
<p>This shows me the duration of every single TCP connection, so I can find the long ones and then
|
|
investigate them in more detail! So useful :D</p>
|
|
<h3 id="use-the-latest-wireshark-version" class="post-heading">
|
|
<a href="#use-the-latest-wireshark-version">
|
|
use the latest Wireshark version
|
|
</a>
|
|
</h3>
|
|
<p>If you haven’t upgraded Wireshark in a while, it’s worth upgrading! I was looking at some HTTP/2
|
|
packets on my work laptop recently and was having a tough time. But then I looked at the docs and
|
|
realized I was running an old version of Wireshark. I upgraded, and Wireshark’s HTTP/2 support had
|
|
really improved in the newest version!</p>
|
|
<h3 id="use-wireshark-to-learn-networking-protocols" class="post-heading">
|
|
<a href="#use-wireshark-to-learn-networking-protocols">
|
|
use Wireshark to learn networking protocols
|
|
</a>
|
|
</h3>
|
|
<p>There’s some networking jargon in this post (“frame”, “tcp port”, “dns response”, “source IP
|
|
address”, “SSL client hello”). I left it in because Wireshark definitely doesn’t abstract networking
|
|
details away from you. That can definitely be intimidating at first!</p>
|
|
<p>But Wireshark can actually be a great tool to learn a bit more about networking protocols. For
|
|
example, I don’t know too much about the details of how the TLS/SSL protocol works! But I can see that
|
|
the first two packets are “client hello” and “server hello”, and it makes the protocol seem less
|
|
like a scary mystery and more like a concrete thing that I can easily look at the details of.</p>
|
|
<h3 id="that-s-all-for-now" class="post-heading">
|
|
<a href="#that-s-all-for-now">
|
|
that’s all for now
|
|
</a>
|
|
</h3>
|
|
<p>Wireshark has a TON of features and I definitely only use a small fraction of its features. The 5
|
|
tricks I’ve described here are probably 95% of what I use Wireshark for – you only need to know a
|
|
little Wireshark to start using it to debug networking issues!</p>
|
|
|
|
</main>
|
|
|
|
<footer>
|
|
|
|
<style type="text/css">
|
|
#mc_embed_signup{background:#fff; clear:left; font:14px Helvetica,Arial,sans-serif; display: inline;}
|
|
#mc_embed_signup {
|
|
display: inline;
|
|
}
|
|
#mc_embed_signup input.button {
|
|
background: #ff5e00;
|
|
display: inline;
|
|
color: white;
|
|
padding: 6px 12px;
|
|
}
|
|
</style>
|
|
<div class="sharing">
|
|
|
|
<style>
|
|
.form-inline {
|
|
display:flex; flex-flow: row wrap; justify-content: center;
|
|
}
|
|
.form-inline input, .form-inline span {
|
|
padding: 10px;
|
|
}
|
|
.form-inline input {
|
|
display:inline;
|
|
max-width:30%;
|
|
margin: 0 10px 0 0;
|
|
background-color: #fff;
|
|
border: 1px solid #ddd;
|
|
border-radius: 5px;
|
|
padding: 10px;
|
|
}
|
|
button {
|
|
background-color: #f50;
|
|
box-shadow: none;
|
|
border: 0;
|
|
border-radius: 5px;
|
|
color: white;
|
|
padding: 5px 10px;
|
|
}
|
|
@media (max-width: 800px) {
|
|
.form-inline input {
|
|
margin: 10px 0;
|
|
max-width:100% !important;
|
|
}
|
|
.form-inline {
|
|
flex-direction: column;
|
|
align-items: stretch;
|
|
}
|
|
}
|
|
</style>
|
|
|
|
<div align="center">
|
|
<form class="form-inline" action="https://app.convertkit.com/forms/1052396/subscriptions" method="post" data-uid="8884355abb" data-format="inline" data-version="5">
|
|
<span> Want a weekly digest of this blog?</span>
|
|
<input name="email_address" type="text" placeholder="Email address" />
|
|
<button type="submit" data-element="submit">Subscribe</button>
|
|
</form>
|
|
</div>
|
|
|
|
|
|
</div>
|
|
|
|
<p class="meta">
|
|
|
|
<a class="basic-alignment left" href="https://jvns.ca/blog/2018/05/11/batch-editing-files-with-ed/" title="Previous Post: Batch editing files with ed">Batch editing files with ed</a>
|
|
|
|
|
|
<a class="basic-alignment right" href="https://jvns.ca/blog/2018/07/11/netdev-day-1--ipsec/" title="Next Post: netdev day 1: IPsec!">netdev day 1: IPsec!</a>
|
|
|
|
</p>
|
|
</footer>
|
|
|
|
</article>
|
|
</div>
|
|
|
|
</div>
|
|
</div>
|
|
<nav role="navigation" class="footer-nav"> <a href="/">Archives</a>
|
|
</nav>
|
|
<footer role="contentinfo"><span class="credit">© Julia Evans. </span>
|
|
<span>If you like this, you may like <a href="https://web.archive.org/web/20181228051203/http://www.uliaea.ca/">Ulia Ea</a> or, more seriously, this list of <a href="https://jvns.ca/blogroll">blogs I love</a> or some <a href="https://jvns.ca/bookshelf">books I've read</a>. <br>
|
|
<p class="rc-scout__text"><i class="rc-scout__logo"></i>
|
|
You might also like the <a class="rc-scout__link" href="https://www.recurse.com/scout/click?t=546ea46360584b522270b8c3e5d830f8">Recurse Center</a>, my very favorite programming community <a href="/categories/hackerschool/">(my posts about it)</a></p>
|
|
</span>
|
|
<style class="rc-scout__style" type="text/css">.rc-scout{display:block;padding:0;border:0;margin:0;}.rc-scout__text{display:block;padding:0;border:0;margin:0;height:100%;font-size:100%;}.rc-scout__logo{display:inline-block;padding:0;border:0;margin:0;width:0.85em;height:0.85em;background:no-repeat center url('data:image/svg+xml;utf8,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%20viewBox%3D%220%200%2012%2015%22%3E%3Crect%20x%3D%220%22%20y%3D%220%22%20width%3D%2212%22%20height%3D%2210%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%221%22%20y%3D%221%22%20width%3D%2210%22%20height%3D%228%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%222%22%20y%3D%222%22%20width%3D%228%22%20height%3D%226%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%222%22%20y%3D%223%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%224%22%20y%3D%223%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%226%22%20y%3D%223%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%223%22%20y%3D%225%22%20width%3D%222%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%226%22%20y%3D%225%22%20width%3D%222%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%224%22%20y%3D%229%22%20width%3D%224%22%20height%3D%223%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%221%22%20y%3D%2211%22%20width%3D%2210%22%20height%3D%224%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%220%22%20y%3D%2212%22%20width%3D%2212%22%20height%3D%223%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%222%22%20y%3D%2213%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%223%22%20y%3D%2212%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%224%22%20y%3D%2213%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%225%22%20y%3D%2212%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%226%22%20y%3D%2213%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%227%22%20y%3D%2212%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%228%22%20y%3D%2213%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%229%22%20y%3D%2212%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3C%2Fsvg%3E');}.rc-scout__link:link,.rc-scout__link:visited{color:#61ae24;text-decoration:underline;}.rc-scout__link:hover,.rc-scout__link:active{color:#4e8b1d;}</style>
|
|
</footer>
|
|
<script type="text/rocketscript">
|
|
(function(){
|
|
var twitterWidgets = document.createElement('script');
|
|
twitterWidgets.type = 'text/javascript';
|
|
twitterWidgets.async = true;
|
|
twitterWidgets.src = 'http://platform.twitter.com/widgets.js';
|
|
document.getElementsByTagName('head')[0].appendChild(twitterWidgets);
|
|
})();
|
|
</script>
|
|
</div>
|
|
</body>
|
|
</html>
|
|
|