Software Product Description
- Data can be captured "off the wire" from a live network connection, or read from a capture file.
- Wireshark can read capture files from tcpdump (libpcap), NAI's Sniffer (compressed and uncompressed), Sniffer Pro, NetXray, Sun snoop and atmsnoop, Shomiti/Finisar Surveyor, AIX's iptrace, Microsoft's Network Monitor, Novell's LANalyzer, RADCOM's WAN/LAN Analyzer, HP-UX nettl, i4btrace from the ISDN4BSD project, Cisco Secure IDS iplog, the pppd log (pppdump-format), the AG Group's/WildPacket's EtherPeek/TokenPeek/AiroPeek, or Visual Networks' Visual UpTime. It can also read traces made from Lucent/Ascend WAN routers and Toshiba ISDN routers, as well as the text output from VMS's TCPIPtrace utility and the DBS Etherwatch utility for VMS. Any of these files can be compressed with gzip and Ethereal will decompress them on the fly.
- Live data can be read from Ethernet, FDDI, PPP, Token-Ring, IEEE 802.11, Classical IP over ATM, and loopback interfaces (at least on some platforms; not all of those types are supported on all platforms).
- Captured network data can be browsed via a GUI, or via the TTY-mode "tethereal" program.
- Capture files can be programmatically edited or converted via command-line switches to the "editcap" program.
- 602 protocols can currently be dissected
- Output can be saved or printed as plain text or PostScript.
- Data display can be refined using a display filter.
- Display filters can also be used to selectively highlight and color packet summary information.
- All or part of each captured network trace can be saved to disk.
"An Excellent Open Source Application..."
Reviewer: -Dr. Nemo
Review Date: 2010-04-04
Other Thoughts: It is a powerful tool to analyze thoroughly and immediately the inside, the problems and the tracks of what happens every time you are surfing in Internet and what is download or upload in cyberspace of and who are listening to each click do on the Web.
For the newbies it will seem complex, but the application has a good user's help, and links to the tutorials offered on the site of the author.
Warning: Wireshark will not work if is not installed WinPcap 4.1.1, standalone application that can be downloaded when Wireshark prompts for it during installation or when you decide. Personally, we had to go to the mirror of WinPcap in Taiwan, because there were serious difficulties with the site developer.