Skip to content

wireshark

Protocol analyser — decodes captured traffic across two thousand protocols

What it does

Reads captured network traffic, live or from a file, and decodes it down to individual protocol fields with a filter language for finding what matters in a large capture. tshark is the same engine without the interface.

Why you would want it

It is the tool every other capture in this catalog feeds into. It reads tcpdump's files, it reads the pcap output from the Bluetooth and 802.11 tooling, and its dissectors cover far more than networking -- including radio protocols that arrive as pcap from an SDR decoder.

Before it will work

Membership of the wireshark group for non-root capture, which the system modification above describes. Reading a capture file needs nothing at all.

How it installs

  • apt: wireshark, tshark, libcap2-bin

What it changes on your machine

  • group_membership — Adds the operator to the wireshark group so capture works without root
  • Debian's wireshark-common package asks at install time whether non-root users may capture. Answering yes sets dumpcap setuid-free with CAP_NET_RAW and CAP_NET_ADMIN, and restricts execution to the wireshark group; membership of that group is then equivalent to the ability to capture all traffic on the machine. Group membership does not apply to a session already open -- log out and back in.
  • undo: sudo gpasswd -d $USER wireshark && sudo dpkg-reconfigure wireshark-common

Known problems

The debconf question about non-root capture is asked once, at install, and answering it wrongly is fixed with dpkg-reconfigure wireshark-common rather than by reinstalling. Its display-filter syntax is not tcpdump's capture-filter syntax and the two are easily confused. Very large captures are memory-hungry; use tshark or split the file.

Keeping it current

  • probe: apt policy
  • strategy: apt_upgrade

Source: catalog/packages/wireshark.yaml