SlideShare une entreprise Scribd logo
1  sur  10
Télécharger pour lire hors ligne
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
: ‫عنوان‬wireshark
‫عباسی‬ ‫مهرداد‬
.MehrdadLinux@Gmail Com
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
What is network packet
● Data 0 – 1
● Media
● packet
● packet-switched network
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
What is packet analyzer?
● packet analyzer
– network analyzer
– protocol analyzer
– packet sniffer
● particular types of networks
– Ethernet sniffer
– wireless sniffer
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
Packet sniffers can
● Analyze network problems
● Detect network intrusion attempts
● Detect network misuse by internal and external users
● Documenting regulatory compliance through logging all perimeter and endpoint traffic
● Gain information for effecting a network intrusion
● Isolate exploited systems
● Monitor WAN bandwidth utilization
● Monitor network usage (including internal and external users and systems)
● Monitor data-in-motion
● Monitor WAN and endpoint security status
● Gather and report network statistics
● Filter suspect content from network traffic
● Serve as primary data source for day-to-day network monitoring and management
● Spy on other network users and collect sensitive information such as login details or users cookies (depending on any content encryption methods that may be in use)
● Reverse engineer proprietary protocols used over the network
● Debug client/server communications
● Debug network protocol implementations
● Verify adds, moves and changes
● Verify internal control system effectiveness (firewalls, access control, Web filter, spam filter, proxy)
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
Notable packet analyzers
● Cain and Abel
● Capsa Network Analyzer
● Carnivore (FBI)
● CommView
● dSniff
● ettercap
● Fiddler
● Kismet
● Lanmeter
● Microsoft Network Monitor
● Microsoft Message Analyzer
● NarusInsight
● NetScout Systems nGenius Infinistream
● ngrep, Network Grep
● OmniPeek
● Riverbed SteelCentral Packet Analyzer (formerly known as Cascade Pilot)
● Riverbed SteelCentral Transaction Analyzer (formerly known as OPNET ATX and ACE)
● SkyGrabber
● snoop
● tcpdump
● Wireshark (formerly known as Ethereal)
● Xplico Open source Network Forensic Analysis Tool
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
What is Wireshark?
● Wireshark is a free and open-source packet analyzer.
● Developer(s) The Wireshark team
● Stable release 1.12.7 / 12 August 2015; 45 days ago
● Written in C (and C++ in the development version)
● Operating system Cross-platform
● Type Packet analyzer
● License GNU GPL
● Website www.wireshark.org
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
Wireshark History
● 1990s, Gerald Combs
● a computer science graduate of the University of Missouri–Kansas City
● was working for a small Internet service provider
● The commercial protocol analysis products at the time were priced around $1500
● did not run on the company's primary platforms (Solaris and Linux
● began writing Ethereal and released the first version around 1998
● The Ethereal trademark is owned by Network Integration Services
● In May 2006, Combs accepted a job with CACE Technologies. Combs still held copyright on most of Ethereal's
source code (and the rest was re-distributable under the GNU GPL), so he used the contents of the Ethereal
Subversion repository as the basis for the Wireshark repository. However, he did not own the Ethereal
trademark, so he changed the name to Wireshark
● In 2010 Riverbed Technology purchased CACE and took over as the primary sponsor of Wireshark. Ethereal
development has ceased, and an Ethereal security advisory recommended switching to Wireshark
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
Wireshark Developer
● Over 850 Developer
● Windows Installer (64-bit)
● Windows Installer (32-bit)
● Windows PortableApps (32-bit)
● OS X 10.6 and later Intel 64-bit .dmg
● OS X 10.6 and later Intel 32-bit .dmg
● Source Code
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
Wireshark doc
● Online doc
● Offline doc
● books
● Wireshark Certified Network Analyst (WCNA) Program
.MehrdadLinux@Gmail Com
‫عباسی‬ ‫مهرداد‬
Intro to wireshark
● Menu
● How to cap
● Test filter
● Have fun ...

Contenu connexe

En vedette

Wireshark Traffic Analysis
Wireshark Traffic AnalysisWireshark Traffic Analysis
Wireshark Traffic Analysis
David Sweigert
 

En vedette (16)

Network Forensics: Packet Analysis Using Wireshark
Network Forensics: Packet Analysis Using WiresharkNetwork Forensics: Packet Analysis Using Wireshark
Network Forensics: Packet Analysis Using Wireshark
 
Wireshark Inroduction Li In
Wireshark Inroduction  Li InWireshark Inroduction  Li In
Wireshark Inroduction Li In
 
Network Analysis Using Wireshark 1
Network Analysis Using Wireshark 1Network Analysis Using Wireshark 1
Network Analysis Using Wireshark 1
 
Wireshark
WiresharkWireshark
Wireshark
 
Wireshark
Wireshark Wireshark
Wireshark
 
Wireshark Tutorial
Wireshark TutorialWireshark Tutorial
Wireshark Tutorial
 
Wireshark course, Ch 02: Introduction to wireshark
Wireshark course, Ch 02: Introduction to wiresharkWireshark course, Ch 02: Introduction to wireshark
Wireshark course, Ch 02: Introduction to wireshark
 
Penetration and hacking training brief
Penetration and hacking training briefPenetration and hacking training brief
Penetration and hacking training brief
 
Wireshark
WiresharkWireshark
Wireshark
 
Wireshark - Basics
Wireshark - BasicsWireshark - Basics
Wireshark - Basics
 
Penetration Testing vs. Vulnerability Scanning
Penetration Testing vs. Vulnerability ScanningPenetration Testing vs. Vulnerability Scanning
Penetration Testing vs. Vulnerability Scanning
 
OSTU - Quickstart Guide for Wireshark (by Tony Fortunato)
OSTU - Quickstart Guide for Wireshark (by Tony Fortunato)OSTU - Quickstart Guide for Wireshark (by Tony Fortunato)
OSTU - Quickstart Guide for Wireshark (by Tony Fortunato)
 
Wireshark Traffic Analysis
Wireshark Traffic AnalysisWireshark Traffic Analysis
Wireshark Traffic Analysis
 
Ch 13: Network Protection Systems
Ch 13: Network Protection SystemsCh 13: Network Protection Systems
Ch 13: Network Protection Systems
 
Practical Packet Analysis: Wireshark
Practical Packet Analysis: Wireshark Practical Packet Analysis: Wireshark
Practical Packet Analysis: Wireshark
 
Network Packet Analysis with Wireshark
Network Packet Analysis with WiresharkNetwork Packet Analysis with Wireshark
Network Packet Analysis with Wireshark
 

Plus de Isfahanlug (20)

Vir
VirVir
Vir
 
405 zsh
405 zsh405 zsh
405 zsh
 
388 wp
388 wp388 wp
388 wp
 
386 wp
386 wp386 wp
386 wp
 
News 940726
News 940726News 940726
News 940726
 
Wp
WpWp
Wp
 
News
NewsNews
News
 
Statrqt 383
Statrqt 383Statrqt 383
Statrqt 383
 
News383
News383News383
News383
 
S378 introduction to robocup & soccer simulation
S378 introduction to robocup & soccer simulationS378 introduction to robocup & soccer simulation
S378 introduction to robocup & soccer simulation
 
S376 uefi
S376 uefiS376 uefi
S376 uefi
 
S377 telegrambot
S377 telegrambotS377 telegrambot
S377 telegrambot
 
92 06-18
92 06-1892 06-18
92 06-18
 
28 5-92
28 5-9228 5-92
28 5-92
 
29 2-92
29 2-9229 2-92
29 2-92
 
14 5-92
14 5-9214 5-92
14 5-92
 
7 5-92
7 5-927 5-92
7 5-92
 
31 4-92
31 4-9231 4-92
31 4-92
 
20 3-92
20 3-9220 3-92
20 3-92
 
23 4-92
23 4-9223 4-92
23 4-92
 

Dernier

Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functions
KarakKing
 
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
ZurliaSoop
 

Dernier (20)

SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptxSKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
 
REMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptxREMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptx
 
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
 
How to setup Pycharm environment for Odoo 17.pptx
How to setup Pycharm environment for Odoo 17.pptxHow to setup Pycharm environment for Odoo 17.pptx
How to setup Pycharm environment for Odoo 17.pptx
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - English
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptx
 
Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxHMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
 
Spatium Project Simulation student brief
Spatium Project Simulation student briefSpatium Project Simulation student brief
Spatium Project Simulation student brief
 
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
 
On National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan FellowsOn National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan Fellows
 
How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17
 
Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functions
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The Basics
 
Sociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning ExhibitSociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning Exhibit
 
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
 
Interdisciplinary_Insights_Data_Collection_Methods.pptx
Interdisciplinary_Insights_Data_Collection_Methods.pptxInterdisciplinary_Insights_Data_Collection_Methods.pptx
Interdisciplinary_Insights_Data_Collection_Methods.pptx
 

Wireshark

  • 1. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ : ‫عنوان‬wireshark ‫عباسی‬ ‫مهرداد‬ .MehrdadLinux@Gmail Com
  • 2. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ What is network packet ● Data 0 – 1 ● Media ● packet ● packet-switched network
  • 3. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ What is packet analyzer? ● packet analyzer – network analyzer – protocol analyzer – packet sniffer ● particular types of networks – Ethernet sniffer – wireless sniffer
  • 4. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ Packet sniffers can ● Analyze network problems ● Detect network intrusion attempts ● Detect network misuse by internal and external users ● Documenting regulatory compliance through logging all perimeter and endpoint traffic ● Gain information for effecting a network intrusion ● Isolate exploited systems ● Monitor WAN bandwidth utilization ● Monitor network usage (including internal and external users and systems) ● Monitor data-in-motion ● Monitor WAN and endpoint security status ● Gather and report network statistics ● Filter suspect content from network traffic ● Serve as primary data source for day-to-day network monitoring and management ● Spy on other network users and collect sensitive information such as login details or users cookies (depending on any content encryption methods that may be in use) ● Reverse engineer proprietary protocols used over the network ● Debug client/server communications ● Debug network protocol implementations ● Verify adds, moves and changes ● Verify internal control system effectiveness (firewalls, access control, Web filter, spam filter, proxy)
  • 5. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ Notable packet analyzers ● Cain and Abel ● Capsa Network Analyzer ● Carnivore (FBI) ● CommView ● dSniff ● ettercap ● Fiddler ● Kismet ● Lanmeter ● Microsoft Network Monitor ● Microsoft Message Analyzer ● NarusInsight ● NetScout Systems nGenius Infinistream ● ngrep, Network Grep ● OmniPeek ● Riverbed SteelCentral Packet Analyzer (formerly known as Cascade Pilot) ● Riverbed SteelCentral Transaction Analyzer (formerly known as OPNET ATX and ACE) ● SkyGrabber ● snoop ● tcpdump ● Wireshark (formerly known as Ethereal) ● Xplico Open source Network Forensic Analysis Tool
  • 6. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ What is Wireshark? ● Wireshark is a free and open-source packet analyzer. ● Developer(s) The Wireshark team ● Stable release 1.12.7 / 12 August 2015; 45 days ago ● Written in C (and C++ in the development version) ● Operating system Cross-platform ● Type Packet analyzer ● License GNU GPL ● Website www.wireshark.org
  • 7. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ Wireshark History ● 1990s, Gerald Combs ● a computer science graduate of the University of Missouri–Kansas City ● was working for a small Internet service provider ● The commercial protocol analysis products at the time were priced around $1500 ● did not run on the company's primary platforms (Solaris and Linux ● began writing Ethereal and released the first version around 1998 ● The Ethereal trademark is owned by Network Integration Services ● In May 2006, Combs accepted a job with CACE Technologies. Combs still held copyright on most of Ethereal's source code (and the rest was re-distributable under the GNU GPL), so he used the contents of the Ethereal Subversion repository as the basis for the Wireshark repository. However, he did not own the Ethereal trademark, so he changed the name to Wireshark ● In 2010 Riverbed Technology purchased CACE and took over as the primary sponsor of Wireshark. Ethereal development has ceased, and an Ethereal security advisory recommended switching to Wireshark
  • 8. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ Wireshark Developer ● Over 850 Developer ● Windows Installer (64-bit) ● Windows Installer (32-bit) ● Windows PortableApps (32-bit) ● OS X 10.6 and later Intel 64-bit .dmg ● OS X 10.6 and later Intel 32-bit .dmg ● Source Code
  • 9. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ Wireshark doc ● Online doc ● Offline doc ● books ● Wireshark Certified Network Analyst (WCNA) Program
  • 10. .MehrdadLinux@Gmail Com ‫عباسی‬ ‫مهرداد‬ Intro to wireshark ● Menu ● How to cap ● Test filter ● Have fun ...