Professional Documents
Culture Documents
THE RIGHT PANEL SHOWS THE PANEL BYTES IN DEFAULT HEXADECIMAL FORMAT
THE TIME COLUMN DISPLAYS THE TIME OF THE PACKETS CAPTURED
THE SORUCE COLUMN AND DESTINATION COLUMN DISPLAYS THE IP ADDRESS OF THE
SENDER AND RECEIVER RESPECTIVELY
THE PROTOCOL COLUMN DISPLAY THE TYPE OF THE PACKET AND THE LENGTH COLUMN
DISPLAY THE LENGTH OF THE PACKETS IN BYTES
THE INFO COLUMN DISPLAYS THE BRIEF OVERVIEW OF THE CAPTURED PACKET
CAPTURE OPTIONS FOR DISPLAYING THE REQUIRED NETWORK PACKETS
HERE WE TYPE THE PAYLOAD IN THE STRING OPTION AND FIND AS WE CAN THE PACKETS
CONTAINING PAYLOAD ARE DISPLAYED HERE
WE USE FILTER HERE AND SAY THE WIRESHARK TO DISPLAY THE PACKETS THAT CONATINS
“http” AND IT CONTROLS THE NETWORK TRAFFIC
WE USE FILTER HERE AND SAY THE WIRESHARK TO DISPLAY THE PACKETS THAT CONATINS
“ARP PROTOCOL “ AND IT CONTROLS THE NETWORK TRAFFIC
WE USE MULTIPLE FILTERING ALSO
IP ADDER COMMAND FOR DISPLAYING THE PACKETS OF THIS IP ADRESS SENT OR RECIVED
Wireshark is a powerful network protocol analyzer that allows you to capture
and interactively browse the traffic running on a computer network. Using
Wireshark's display filter, you can precisely define the criteria for the network
packets you wish to analyze. Here are some common filter commands used in
Wireshark:
Basic Filters:
1. IP Address: Filter packets based on a specific IP address.
- `ip.addr == 192.168.1.1`
6. Filter by Protocol: Filter by a specific protocol (e.g., TCP, UDP, ARP, ICMP).
- `tcp`, `udp`, `arp`, `icmp`
Advanced Filters:
- `==`: Equal to
- `!=`: Not equal to
- `<`, `>`: Less than, greater than
- `<=`, `>=`: Less than or equal to, greater than or equal to
- `tcp.port == 443 and ip.addr == 8.8.8.8`: Filter TCP traffic on port 443 with the
IP address 8.8.8.8.
- `ip.addr == 192.168.0.1 and not udp`: Filter packets with the IP address
192.168.0.1 that are not UDP.
- `tcp contains "password"`: Filter TCP packets containing the string
"password".
These are just a few examples of the filtering capabilities in Wireshark. You
can create complex filters by combining different criteria to precisely pinpoint
the packets you want to analyze.
Wireshark Cheat Sheet - Commands, Captures, Filters, Shortcuts & FAQs (comparitech.com)
DisplayFilters (wireshark.org)