Copyright
Acquiring Editor: Chris Katsaropoulos
Development Editor: Benjamin Rearick
Project Manager: Mohana Natarajan
Syngress is an imprint of Elsevier
225 Wyman Street, Waltham, MA 02451, USA
First published 2013
Copyright 2013 Elsevier Inc. All rights reserved.
No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or any information storage and retrieval system, without permission in writing from the publisher. Details on how to seek permission, further information about the Publishers permissions policies and our arrangement with organizations such as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our website: www.elsevier.com/permissions.
This book and the individual contributions contained in it are protected under copyright by the Publisher (other than as may be noted herein).
Notices
Knowledge and best practice in this field are constantly changing. As new research and experience broaden our understanding, changes in research methods, professional practices, or medical treatment may become necessary.
Practitioners and researchers must always rely on their own experience and knowledge in evaluating and using any information, methods, compounds, or experiments described herein. In using such information or methods they should be mindful of their own safety and the safety of others, including parties for whom they have a professional responsibility.
To the fullest extent of the law, neither the Publisher nor the authors, contributors, or editors, assume any liability for any injury and/or damage to persons or property as a matter of products liability, negligence or otherwise, or from any use or operation of any methods, products, instructions, or ideas contained in the material herein.
British Library Cataloguing in Publication Data
A catalogue record for this book is available from the British Library
Library of Congress Cataloging-in-Publication Data
A catalog record for this book is available from the Library of Congress
ISBN: 978-0-12-410413-6
For information on all Syngress publications visit our website at www.syngress.com
Dedication
This book is dedicated to my wonderful children, Dylan Shimonski and Vienna Shimonski. I love you!
Preface
Welcome to The Wireshark Field Guide: Analyzing and Troubleshooting Network Traffic book, your guide to get up to speed using Wireshark in a quick and efficient manner. This book provides hackers, pen testers, and network administrators with practical guidance on capturing and interactively browsing the traffic running on a computer network. Wireshark is the worlds foremost network protocol analyzer, with a rich feature set that includes deep inspection of hundreds of protocols, live capture, offline analysis, and many other features.
Wireshark is a multiplatform application that can be set up and put to work in minutes to help analyze and troubleshoot some of the most complex security problems found today. This book covers the installation, configuration, and use of this powerful tool. It provides readers with the hands-on skills to be more productive with Wireshark as they drill down into the information contained in real-time network traffic.
Learn the fundamentals of using Wireshark in a concise field manual.
Quickly create functional filters that will allow you to get to work quickly on solving problems.
Understand the myriad of options and the deep functionality of Wireshark to get working quicker.
Solve common problems seen in networks today with what is taught in this guide.
Learn some advanced features, methods, and helpful ways to work quicker and more efficient.
The goal of this book is to teach the basics quickly in a very short format publication. Use the following link and similar other links found at the books companion website www.learnwireshark.com.
About the Author
Robert Shimonski (www.shimonski.com) is a best-selling author and editor with over 15 years experience developing, producing, and distributing print media in the form of books, magazines, and periodicals. To date, Rob has successfully created over 100 books that are currently in circulation. Rob has worked for countless companies including CompTIA, Entrepreneur Magazine, Microsoft, McGraw-Hill Education, Cisco, the National Security Agency, and Digidesign.
Rob also has over 15 years experience in direct support of network infrastructures and systems and has spent a considerable amount of that time in leading teams in operational support and engineering architecture. Rob authored the award-winning Syngress book Sniffer Pro Network Optimization and Troubleshooting Handbook back in 2002. He has also contributed to many other network and security-related publications on penetration, security design, network analysis, and systems engineering. He can be reached online at www.shimonski.com or at www.learnwireshark.com.
Acknowledgment
I would like to thank all who made this book possible. Special thanks to Pete Cheung for his technical help in creating this book and to Chris and Ben for their assistance in producing this book.
Introduction
Welcome to the Syngress Wireshark Field Guide, your indispensable companion to using Wireshark successfully and solving problems with one of the most commonly used tools in the networking arena today. In this concise text, I will cover how to acquire Wireshark, what you need to know about it to get it up and running and then using it to help solve problems.
For over two decades, the need for an understanding of protocol analysis has grown as the networks we rely on to connect our computers, mobile devices, and systems to use the Internet, access the cloud, and work within our corporate networks have also grown. As more reliance on using the network becomes the norm, solving problems quickly is also becoming increasingly more important.
As we will learn in this book, Wireshark (as well as other protocol analysis tools) is used often to help find and solve problems on internetworks for all sizes. In this book, we will cover the following sections:
About Wireshark
Experienced network technicians, operators, and engineers across the globe use Wireshark and tools of its kind to solve problems and we will cover not only the nuts and bolts of using it but also why we do. In this section, we will briefly go over the history of Wireshark as well as to discuss the use of packet capture and analysis in the field of networking. First, we need to understand the history of Wireshark and packet capture and analysis to get a solid understanding of the purpose of using this tool. An in-depth look at Wireshark, its features, and the toolset are covered as well as a granular look at the specifics of why protocol capture and analysis is so critical to solving problems.