Files
nexus/sreweekly/articles/130/04-how-i-use-wireshark.html
2026-09-12 17:23:01 +08:00

333 lines
19 KiB
HTML

<!DOCTYPE html>
<html class="no-js" lang="en">
<head>
<meta charset="utf-8">
<title>How I use Wireshark</title>
<meta name="author" content="Julia Evans">
<meta name="HandheldFriendly" content="True">
<meta name="MobileOptimized" content="320">
<meta name="description" content="How I use Wireshark">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta property="og:title" content='How I use Wireshark'>
<meta property="og:type" content="website" />
<meta property="og:url" content="https://jvns.ca/blog/2018/06/19/what-i-use-wireshark-for/" />
<meta property="og:site_name" content="Julia Evans" />
<link rel="canonical" href="https://jvns.ca/blog/2018/06/19/what-i-use-wireshark-for/">
<link href="/favicon.ico" rel="icon">
<link href="/stylesheets/screen.css" rel="preload" type="text/css" as="style">
<link href="/stylesheets/screen.css" media="screen, projection" rel="stylesheet" type="text/css">
<link href="/stylesheets/print.css" media="print" rel="stylesheet" type="text/css">
<link href="/atom.xml" rel="alternate" title="Julia Evans" type="application/atom+xml">
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/katex@0.16.4/dist/katex.min.css" integrity="sha384-vKruj+a13U8yHIkAyGgK1J3ArTLzrFGBbBc0tDp4ad/EyewESeXE/Iv67Aj8gKZ0" crossorigin="anonymous">
<script defer data-domain="jvns.ca" src="https://plausible.io/js/script.js"></script>
<script defer src="https://cdn.jsdelivr.net/npm/katex@0.16.4/dist/katex.min.js" integrity="sha384-PwRUT/YqbnEjkZO0zZxNqcxACrXe+j766U2amXcgMg5457rve2Y7I6ZJSm2A0mS4" crossorigin="anonymous"></script>
<script defer src="https://cdn.jsdelivr.net/npm/katex@0.16.4/dist/contrib/auto-render.min.js" integrity="sha384-+VBxd3r6XgURycqtZ117nYw44OOcIax56Z4dCRWbxyPt0Koah1uHoK0o4+/RRE05" crossorigin="anonymous" onload="renderMathInElement(document.body);"></script>
<script defer type="text/javascript">
window.heap=window.heap||[],heap.load=function(e,t){window.heap.appid=e,window.heap.config=t=t||{};var r=document.createElement("script");r.type="text/javascript",r.async=!0,r.src="https://cdn.heapanalytics.com/js/heap-"+e+".js";var a=document.getElementsByTagName("script")[0];a.parentNode.insertBefore(r,a);for(var n=function(e){return function(){heap.push([e].concat(Array.prototype.slice.call(arguments,0)))}},p=["addEventProperties","addUserProperties","clearEventProperties","identify","resetIdentity","removeEventProperty","setEventProperties","track","unsetEventProperty"],o=0;o<p.length;o++)heap[p[o]]=n(p[o])};
heap.load("2242143965");
</script>
</head>
<body>
<div id="skiptocontent">
<a href="#main">Skip to main content</a>
</div>
<div id="wrap">
<header role="banner">
<hgroup>
<h1><a href="/">Julia Evans</a></h1>
</hgroup>
<ul class="header-links">
<li><a href="/about">About</a></li>
<li><a href="/talks">Talks</a></li>
<li><a href="/projects/">Projects</a></li>
<li><a rel="me" href="https://social.jvns.ca/@b0rk">Mastodon</a></li>
<li><a href="https://bsky.app/profile/b0rk.jvns.ca">Bluesky</a></li>
<li><a href="https://github.com/jvns">Github</a></li>
</ul>
</header>
<nav role="navigation" class="header-nav"><ul class="main-navigation">
<li><a href="/categories/favorite/">Favorites</a></li>
<li><a href="/til/">TIL</a></li>
<li><a href="https://wizardzines.com">Zines</a></li>
<li class="subscription" data-subscription="rss"><a href="/atom.xml" rel="subscribe-rss" title="subscribe via RSS">RSS</a></li>
</ul>
</nav>
<div id="main">
<div id="content">
<div>
<article class="hentry" role="article">
<header>
<h1 class="entry-title">How I use Wireshark</h1>
<div class="post-tags">
</div>
<p class="meta sans">
<time class="date" datetime="2018-06-19T00:28:24" pubdate data-updated="true">
June 19, 2018
</time>
</p>
</header>
<main>
<p>Hello! I was using Wireshark to debug a networking problem today, and I realized I&rsquo;ve never written
a blog post about Wireshark! Wireshark is one of my very favourite networking tools, so let&rsquo;s fix
that :)</p>
<p>Wireshark is a really powerful and complicated tool, but in practice I only know how to do a very
small number of things with it, and those things are really useful! So in this blog post, I&rsquo;ll
explain the 5 main things I use Wireshark for, and hopefully you&rsquo;ll have a slightly clearer idea of
why it&rsquo;s useful.</p>
<h3 id="what-s-wireshark" class="post-heading">
<a href="#what-s-wireshark">
what&rsquo;s Wireshark?
</a>
</h3>
<p><a href="https://www.wireshark.org/">Wireshark</a> is a graphical network packet analysis tool.</p>
<p>On Mac, you can download &amp; install it from their homepage, and on Debian-based distros you can
install it with <code>sudo apt install wireshark</code>. There&rsquo;s also an official
<a href="https://launchpad.net/~wireshark-dev/+archive/ubuntu/stable">wireshark-dev PPA</a> you can use to get
more up-to-date Wireshark versions.</p>
<p>Wireshark looks like this, and it can be a little overwhelming at first. There&rsquo;s a slightly
mysterious search box, and a lot of packets, and how do you even use this thing?</p>
<p><a href="https://jvns.ca/images/wireshark_screenshot.png"><img src="https://jvns.ca/images/wireshark_screenshot.png"></a></p>
<h3 id="use-wireshark-to-analyze-pcap-files" class="post-heading">
<a href="#use-wireshark-to-analyze-pcap-files">
Use Wireshark to analyze pcap files
</a>
</h3>
<p>Usually I use Wireshark to debug networking problems in production. My Wireshark workflow
is:</p>
<ol>
<li>Capture packets with tcpdump (typically something like <code>sudo tcpdump port 443 -w output.pcap</code></li>
<li>scp the pcap file to my laptop (<code>scp host:~/output.pcap .</code>)</li>
<li>Open the pcap file in Wireshark (<code>wireshark output.pcap</code>)</li>
</ol>
<p>That&rsquo;s pretty simple! But once you have a pcap file with a bunch of packets on your laptop, what do
you do with it?</p>
<h3 id="look-at-a-single-tcp-connection" class="post-heading">
<a href="#look-at-a-single-tcp-connection">
Look at a single TCP connection
</a>
</h3>
<p>Often when I&rsquo;m debugging something in Wireshark, what&rsquo;s happened is that there&rsquo;s some TCP
connection, and something went wrong with the connection for some reason. Wireshark
makes it really easy to look at the lifetime of a TCP connection and see what happened!</p>
<p>You can do that by right clicking on a packet and clicking &ldquo;Conversation filter&rdquo; -&gt; &ldquo;TCP&rdquo;.</p>
<p><a href="https://jvns.ca/images/wireshark_filter.png"><img src="https://jvns.ca/images/wireshark_filter.png"></a></p>
<p>And then Wireshark will just show you other packets from the same TCP connection as that packet!!
Here you&rsquo;ll see a successful SSL connection &ndash; there&rsquo;s are packets that say &ldquo;client hello&rdquo;,
&ldquo;service hello&rdquo;, &ldquo;certificate&rdquo;, &ldquo;server key exchange&rdquo;, which are all part of setting up a SSL
connection. Neat!</p>
<p><a href="https://jvns.ca/images/wireshark_tcp.png"><img src="https://jvns.ca/images/wireshark_tcp.png"></a></p>
<p>I actually used this today to debug an SSL issue &ndash; at work today, some connections were being
reset, and I noticed that after the &ldquo;client hello&rdquo; packet was sent, the client was sending a &ldquo;FIN
ACK&rdquo; packet which terminates the TLS connection. This was useful because I could tell that the
<strong>client</strong> was terminating the connection, not the server! So immediately I knew that the client was
to blame and I could focus my investigations there.</p>
<p>This pattern is pretty typical of how I use Wireshark. Usually there&rsquo;s a client and a server, and
there&rsquo;s a bug or configuration error on either the client or the server. Wireshark is invaluable for
helping me figure out whether I should blame the client or the server :)</p>
<h3 id="decode-as" class="post-heading">
<a href="#decode-as">
&ldquo;Decode as&rdquo;
</a>
</h3>
<p>Wireshark uses the port to try to guess what kind of packet every packet is, and often it does a
good job! If it sees traffic on port 80, it&rsquo;ll assume it&rsquo;s HTTP traffic, and it&rsquo;s usually right.</p>
<p>But sometimes you have HTTP traffic happening on an unusual port, and you need to give Wireshark
some hints. If you right click on a packet and click &ldquo;Decode as&rdquo;, you can tell Wireshark what
protocol packets on that port are and then it&rsquo;ll be much easier to navigate and search.</p>
<h3 id="see-the-contents-of-a-packet" class="post-heading">
<a href="#see-the-contents-of-a-packet">
See the contents of a packet
</a>
</h3>
<p>Wireshark has an AMAZING details view that explains the contents of any packet. Let&rsquo;s take the
&ldquo;client hello&rdquo; packet from the details above. This packet is the first packet sent during a SSL
connection &ndash; the client is saying &ldquo;hello! here I am!&rdquo;.</p>
<p>Wireshark gives you two super useful tools for investigating the contents of a packet. The first one
is this view where you can expand every header the packet has (ethernet header! IP header! TCP
header!) and look at what&rsquo;s in it:</p>
<p><a href="https://jvns.ca/images/wireshark_packet_details_list.png"><img src="https://jvns.ca/images/wireshark_packet_details_list.png"></a></p>
<p>The second view, which is really magical, is this one which shows you the raw bytes of a packet. The
neat thing about this is that if you hover over one of the bytes with your mouse (like here I&rsquo;ve
hovered over <code>tiles.services.mozilla.com</code>), it&rsquo;ll tell you at the bottom of the screen what field
those bytes correspond to here (in this case the &ldquo;Server Name&rdquo; field) and the Wireshark codename for
that field (in this case <code>ssl.handshake.extensions_server_name</code>)</p>
<p><a href="https://jvns.ca/images/wireshark_packet_details.png"><img src="https://jvns.ca/images/wireshark_packet_details.png"></a></p>
<h3 id="search-for-specific-packets" class="post-heading">
<a href="#search-for-specific-packets">
Search for specific packets
</a>
</h3>
<p>Wireshark has a great query language, and you can really easily search for specific packets! I
usually just use really simple queries with Wireshark. Here are a few examples of the kinds of
searches I do:</p>
<ul>
<li><code>frame contains &quot;mozilla&quot;</code> &ndash; search for the string &ldquo;mozilla&rdquo; anywhere in the packet</li>
<li><code>tcp.port == 443</code> &ndash; tcp port is 443</li>
<li><code>dns.resp.len &gt; 0</code> &ndash; all DNS responses</li>
<li><code>ip.addr == 52.7.23.87</code> &ndash; source or dest IP address is 52.7.23.87</li>
</ul>
<p>Wireshark&rsquo;s packet search language is much more powerful than tcpdump&rsquo;s (and it has tab
completion!!), so I&rsquo;ll often capture a large amount of packets with tcpdump (&ldquo;all packets on port
443&rdquo;) and then do some more in depth searching using Wireshark.</p>
<h3 id="see-statistics-on-tcp-connection-duration" class="post-heading">
<a href="#see-statistics-on-tcp-connection-duration">
see statistics on TCP connection duration
</a>
</h3>
<p>Sometimes I want to specifically investigate slow TCP connections. But what if I have a packet
capture file with many thousands of packets?! How do I find the slow TCP connection?</p>
<p>If you click &lsquo;Statistics&rsquo; in the menu then &lsquo;Conversations&rsquo;, Wireshark will give you this amazing
statistics view that looks like this:</p>
<p><a href="https://jvns.ca/images/wireshark_statistics.png"><img src="https://jvns.ca/images/wireshark_statistics.png"></a></p>
<p>This shows me the duration of every single TCP connection, so I can find the long ones and then
investigate them in more detail! So useful :D</p>
<h3 id="use-the-latest-wireshark-version" class="post-heading">
<a href="#use-the-latest-wireshark-version">
use the latest Wireshark version
</a>
</h3>
<p>If you haven&rsquo;t upgraded Wireshark in a while, it&rsquo;s worth upgrading! I was looking at some HTTP/2
packets on my work laptop recently and was having a tough time. But then I looked at the docs and
realized I was running an old version of Wireshark. I upgraded, and Wireshark&rsquo;s HTTP/2 support had
really improved in the newest version!</p>
<h3 id="use-wireshark-to-learn-networking-protocols" class="post-heading">
<a href="#use-wireshark-to-learn-networking-protocols">
use Wireshark to learn networking protocols
</a>
</h3>
<p>There&rsquo;s some networking jargon in this post (&ldquo;frame&rdquo;, &ldquo;tcp port&rdquo;, &ldquo;dns response&rdquo;, &ldquo;source IP
address&rdquo;, &ldquo;SSL client hello&rdquo;). I left it in because Wireshark definitely doesn&rsquo;t abstract networking
details away from you. That can definitely be intimidating at first!</p>
<p>But Wireshark can actually be a great tool to learn a bit more about networking protocols. For
example, I don&rsquo;t know too much about the details of how the TLS/SSL protocol works! But I can see that
the first two packets are &ldquo;client hello&rdquo; and &ldquo;server hello&rdquo;, and it makes the protocol seem less
like a scary mystery and more like a concrete thing that I can easily look at the details of.</p>
<h3 id="that-s-all-for-now" class="post-heading">
<a href="#that-s-all-for-now">
that&rsquo;s all for now
</a>
</h3>
<p>Wireshark has a TON of features and I definitely only use a small fraction of its features. The 5
tricks I&rsquo;ve described here are probably 95% of what I use Wireshark for &ndash; you only need to know a
little Wireshark to start using it to debug networking issues!</p>
</main>
<footer>
<style type="text/css">
#mc_embed_signup{background:#fff; clear:left; font:14px Helvetica,Arial,sans-serif; display: inline;}
#mc_embed_signup {
display: inline;
}
#mc_embed_signup input.button {
background: #ff5e00;
display: inline;
color: white;
padding: 6px 12px;
}
</style>
<div class="sharing">
<style>
.form-inline {
display:flex; flex-flow: row wrap; justify-content: center;
}
.form-inline input, .form-inline span {
padding: 10px;
}
.form-inline input {
display:inline;
max-width:30%;
margin: 0 10px 0 0;
background-color: #fff;
border: 1px solid #ddd;
border-radius: 5px;
padding: 10px;
}
button {
background-color: #f50;
box-shadow: none;
border: 0;
border-radius: 5px;
color: white;
padding: 5px 10px;
}
@media (max-width: 800px) {
.form-inline input {
margin: 10px 0;
max-width:100% !important;
}
.form-inline {
flex-direction: column;
align-items: stretch;
}
}
</style>
<div align="center">
<form class="form-inline" action="https://app.convertkit.com/forms/1052396/subscriptions" method="post" data-uid="8884355abb" data-format="inline" data-version="5">
<span> Want a weekly digest of this blog?</span>
<input name="email_address" type="text" placeholder="Email address" />
<button type="submit" data-element="submit">Subscribe</button>
</form>
</div>
</div>
<p class="meta">
<a class="basic-alignment left" href="https://jvns.ca/blog/2018/05/11/batch-editing-files-with-ed/" title="Previous Post: Batch editing files with ed">Batch editing files with ed</a>
<a class="basic-alignment right" href="https://jvns.ca/blog/2018/07/11/netdev-day-1--ipsec/" title="Next Post: netdev day 1: IPsec!">netdev day 1: IPsec!</a>
</p>
</footer>
</article>
</div>
</div>
</div>
<nav role="navigation" class="footer-nav"> <a href="/">Archives</a>
</nav>
<footer role="contentinfo"><span class="credit">&copy; Julia Evans. </span>
<span>If you like this, you may like <a href="https://web.archive.org/web/20181228051203/http://www.uliaea.ca/">Ulia Ea</a> or, more seriously, this list of <a href="https://jvns.ca/blogroll">blogs I love</a> or some <a href="https://jvns.ca/bookshelf">books I've read</a>. <br>
<p class="rc-scout__text"><i class="rc-scout__logo"></i>
You might also like the <a class="rc-scout__link" href="https://www.recurse.com/scout/click?t=546ea46360584b522270b8c3e5d830f8">Recurse Center</a>, my very favorite programming community <a href="/categories/hackerschool/">(my posts about it)</a></p>
</span>
<style class="rc-scout__style" type="text/css">.rc-scout{display:block;padding:0;border:0;margin:0;}.rc-scout__text{display:block;padding:0;border:0;margin:0;height:100%;font-size:100%;}.rc-scout__logo{display:inline-block;padding:0;border:0;margin:0;width:0.85em;height:0.85em;background:no-repeat center url('data:image/svg+xml;utf8,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%20viewBox%3D%220%200%2012%2015%22%3E%3Crect%20x%3D%220%22%20y%3D%220%22%20width%3D%2212%22%20height%3D%2210%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%221%22%20y%3D%221%22%20width%3D%2210%22%20height%3D%228%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%222%22%20y%3D%222%22%20width%3D%228%22%20height%3D%226%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%222%22%20y%3D%223%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%224%22%20y%3D%223%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%226%22%20y%3D%223%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%223%22%20y%3D%225%22%20width%3D%222%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%226%22%20y%3D%225%22%20width%3D%222%22%20height%3D%221%22%20fill%3D%22%2361ae24%22%3E%3C%2Frect%3E%3Crect%20x%3D%224%22%20y%3D%229%22%20width%3D%224%22%20height%3D%223%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%221%22%20y%3D%2211%22%20width%3D%2210%22%20height%3D%224%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%220%22%20y%3D%2212%22%20width%3D%2212%22%20height%3D%223%22%20fill%3D%22%23000%22%3E%3C%2Frect%3E%3Crect%20x%3D%222%22%20y%3D%2213%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%223%22%20y%3D%2212%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%224%22%20y%3D%2213%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%225%22%20y%3D%2212%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%226%22%20y%3D%2213%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%227%22%20y%3D%2212%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%228%22%20y%3D%2213%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3Crect%20x%3D%229%22%20y%3D%2212%22%20width%3D%221%22%20height%3D%221%22%20fill%3D%22%23fff%22%3E%3C%2Frect%3E%3C%2Fsvg%3E');}.rc-scout__link:link,.rc-scout__link:visited{color:#61ae24;text-decoration:underline;}.rc-scout__link:hover,.rc-scout__link:active{color:#4e8b1d;}</style>
</footer>
<script type="text/rocketscript">
(function(){
var twitterWidgets = document.createElement('script');
twitterWidgets.type = 'text/javascript';
twitterWidgets.async = true;
twitterWidgets.src = 'http://platform.twitter.com/widgets.js';
document.getElementsByTagName('head')[0].appendChild(twitterWidgets);
})();
</script>
</div>
</body>
</html>