Wireshark 64-bit on Vista

Problems? Post here...
Post Reply
User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Wireshark 64-bit on Vista

Post by DNR »

Another popular tool is wireshark, lets see how it does on Vista sp1
File: wireshark-win64-1.2.1.exe - 13.9mb
>It WORKS<

I just sniffed the traffic between my PC and the internet, I also had a wireless network peer-to-peer. I browsed on the internet through the remote computer, moved a file back and forth. Then I checked the packet results, it was typical for wireshark - all the details printed in its usual color format. I was easy to browse through the details of each packet.

You get complete breakdown of
Frames
Ethernet
Internet Protocol
User Datagram Protocol
HyperText Transfer Protocol

As the sniffer captured the wireless traffic to the remote computer and the internet beyond it. I was able to detect nfo:

Source IP: Nomad_2.mshome.net (192.168.0.7)
Host Name: NOMAD_2
OS Major Version: 6 (windows XP is version 5, Vista is 6 - DNR note)
Host Comment: Wardriver

---
ARP information is easy to construct,
Sender MAC address: Nomad_2.mshome.net (00:22:5f:72:6e:b3)
Sender IP address: Nomad_2.mshome.net (192.168.0.7)
Target MAC address: NOMAD_1.mshome.net (00:90:4b:f1:f9:75)
Target IP address: NOMAD_1.mshome.net (192.168.0.1)
---
I spot the packet when I tell windows to discover the wireless network I was on
src port ssdp (1900) ..Man:"ssdp:discover"\r\n
---

I dissected the packets for Session ID , I even find SEQ/ACK analysis
"This is an ACK to the segment in frame: 632
The RTT to ACK the segment was: 0.498118000 seconds"
--
I detected the name of the document I was requesting from the remote computer

"Level of Interest: Find File Both Directory Info (260)
Search Pattern: \scada.zip"
--

I got a hard-on checking out the expert filters under the Analyze Tab
Under the Statistics Tab you'll find a lot of quick helpful data dumps, check out the End Points.

All the same colors, preferences settings, and it was fast!
Make sure you download the correct version - it will prompt you to get the 64-bit version if it detects Vista - I tried to run the older version of wireshark - no go!

At this time, the Wlan Traffic Statistics did not work?!

[/quote]
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

Post Reply