Capture:

 

 

Go to the Capture Menu on your toolbar:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/7896AA17.tmp

 

 

Select Options:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/6B7F33D.tmp

 

See the Options Interface:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/3B4AE553.tmp

 

In order to listen to traffic from other sources (Make sure you have permission to do so) check to make sure Promiscuous mode is enabled:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/AE1C9DD9.tmp

 

Click the “Start” button

 

You can start seeing traffic being Captured:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/402F964F.tmp

Look at the screen and see all of the icons:

 

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/73D00435.tmp

 

 

Main toolbar items:

 

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/E487390B.tmp

 

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/ED460251.tmp

 

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/94DE0987.tmp

 

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/48A2342D.tmp

 

Checkout this page for more information: https://www.wireshark.org/docs/wsug_html_chunked/ChUseMainToolbarSection.html

Different Types of Filters:

  • Display
  • Capture

 

Display Filter:

 

The Display Filter can be found right under the Toolbar icons:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/B2C603C3.tmp

 

Capture Filter:

If you go to “Capture Options” either on the Toolbar or by clicking “Capture”:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/85D3F5C9.tmp

 

The Capture Filters are right here:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/5852E3BF.tmp

 

 

How it works:

 

In the search bar you can type something to focus more of what you want.

 

For example I type ICMP and it will focus more of what I typed in the filter

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/13726325.tmp

 

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/F556257B.tmp

 

 

Invalid Filter:

 

Indicated by being “Red”

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/2B585841.tmp

 

Valid Filter:

 

Indicated by being “Green”

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/825B04F7.tmp

 

 

Filtering can get more combuersome,

 

For more information on how to use it go to:https://wiki.wireshark.org/DisplayFilters

 

What is a Packet?:

 

A package of information that you’re going to send to another computer.

 

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/B00711D.tmp

 

TCP:

 

 

IPV4:

 

This is the destination and return address information.

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/C5627E33.tmp

 

Ethernet:

Whenever your message is packaged up and ready to be sent, in this case you send to your router and then another router and eventually gets to where it needs to be.

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/E3A109B9.tmp

 

Frame:

The point where the software becomes real. Meaning the information that is 1s and 0s eventually get converted into meaningful information.

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/E45F4D2F.tmp

 

TCP Handshake:

 

SYN – SYN, ACK – ACK

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/1E083E15.tmp

 

Wireshark Example:

SYN:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/4171EDEB.tmp

 

SYN, ACK:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/4E37EA31.tmp

 

ACK:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/5CE49C67.tmp

 

This is where the client heard the message from the server, and is sending back to server a notice that everything can proceed.

 

FIN – FIN , ACK -FIN:

Functions similiarly as above:

/var/folders/4r/jqjqmpys6hgcvp_4_927mwtc0000gn/T/com.microsoft.Word/Content.MSO/F2C1AA0D.tmp