Part 2: Wireshark - GUI Packet Analyzer
What is Wireshark?
- Open-source, cross-platform GUI tool
- Provides detailed protocol breakdown
- Color-coded packet display
- Advanced filtering and analysis
- Can save/import captures (.pcap files)
Starting Wireshark
sudo wireshark⚠️ Important: Must use sudo for packet capture permissions
Wireshark GUI Components
The interface has 5 major parts:
1. Command Menu
- Top menu bar: File, Edit, View, Go, Capture, Analyze, Statistics
- Access to all functions
2. Display Filter Bar
- Text field below menu
- Enter filter expressions
- Shows only packets matching criteria
3. Packet-Listing Window (Top Pane)
- One-line summary per packet
- Columns:
- No.: Packet number
- Time: Timestamp
- Source: Source IP/MAC
- Destination: Destination IP/MAC
- Protocol: Protocol type
- Length: Packet size (bytes)
- Info: Summary information
4. Packet-Detail Window (Middle Pane)
- Detailed protocol breakdown
- Expandable tree structure
- Shows all protocol layers:
- Frame (physical layer)
- Ethernet (data link layer)
- IP (network layer)
- TCP/UDP (transport layer)
- Application data
5. Packet-Content Window (Bottom Pane)
- Raw packet data
- Two views:
- Hexadecimal: Raw bytes
- ASCII: Text representation
Analogy: These windows are like different zoom levels on a microscope - packet-listing shows many cells, packet-detail zooms into structure, packet-content shows the raw DNA.
Wireshark Workflow
Step-by-Step:
-
Start Wireshark:
sudo wireshark -
Select Interface:
- Click "Capture Interfaces" icon (left side)
- Choose
eth0(or your active NIC) - Click "Close"
-
Generate Traffic:
- Open web browser
- Visit websites (e.g., www.google.com)
-
Start Capture:
- Click "Start Capture" icon (shark fin/play button)
- Watch packets appear in real-time
-
Stop Capture:
- Click "Stop Capture" icon (red square)
-
Save Capture (Optional):
- File → Save As
- Choose .pcap or .pcapng format
Wireshark Color Coding
Wireshark uses colors to identify packet types quickly.
Common Colors:
| Color | Packet Type |
|---|---|
| Light Purple | TCP traffic |
| Light Blue | UDP traffic |
| Light Green | HTTP traffic |
| Yellow | ICMP traffic (ping) |
| Black | TCP packets with problems/errors |
| Light Pink | ICMP errors |
| Dark Gray | TCP retransmissions |
View All Color Rules:
- Menu:
View → Coloring Rules
Tip: Customize colors in Preferences if default scheme doesn't work for you
Part 3: Display Filters in Wireshark
What are Display Filters?
- Show only packets matching specific criteria
- Don't delete other packets (just hide them)
- Applied after capture
- Different from capture filters
Operators
Comparison Operators
| Operator | Meaning | Example |
|---|---|---|
== | Equal to | ip.src==192.168.1.1 |
!= | Not equal to | ip.src!=192.168.1.1 |
> | Greater than | frame.len>1000 |
>= | Greater than or equal | frame.len>=500 |
< | Less than | frame.len<100 |
<= | Less than or equal | frame.len<=1500 |
Logical Operators
| Operator | Meaning | Example |
|---|---|---|
&& or and | Both conditions true (AND) | tcp && ip.src==192.168.1.1 |
| or or | Either condition true (OR) | icmp || arp |
! or not | Condition is false (NOT) | !tcp |
IP Address Filtering
Filter Types:
| Filter | Description | Example |
|---|---|---|
ip.addr | Packets to/from this IP | ip.addr==192.168.1.100 |
ip.src | Packets FROM this source | ip.src==192.168.1.100 |
ip.dst | Packets TO this destination | ip.dst==8.8.8.8 |
Examples:
# Show all traffic to/from specific IP
ip.addr==203.131.212.198
# Show packets FROM specific source
ip.src==192.168.1.100
# Show packets TO specific destination
ip.dst==8.8.8.8
# Combine: packets FROM 192.168.1.1 OR TO 8.8.8.8
ip.src==192.168.1.1 || ip.dst==8.8.8.8
# Packets between two IPs
ip.addr==192.168.1.1 && ip.addr==192.168.1.2
Protocol Filtering
Common Protocol Filters:
| Filter | Description |
|---|---|
arp | Show only ARP packets |
icmp | Show only ICMP packets (ping) |
tcp | Show only TCP packets |
udp | Show only UDP packets |
http | Show only HTTP traffic |
https | Show only HTTPS traffic |
dns | Show only DNS queries/responses |
ssh | Show only SSH traffic |
Examples:
# Show only TCP traffic
tcp
# Show only ping packets
icmp
# Show only ARP requests
arp
# Show HTTP or HTTPS
http || https
# Show TCP on specific port
tcp.port==80
# Show DNS queries
dns
Port Filtering
# Specific port (either source or destination)
tcp.port==80
# Source port
tcp.srcport==443
# Destination port
tcp.dstport==22
# Port range
tcp.port>=1000 && tcp.port<=2000
Frame Length Filtering
# Packets smaller than 1000 bytes
frame.len < 1000
# Packets larger than 500 bytes
frame.len > 500
# Packets between 500-1500 bytes
frame.len > 500 && frame.len < 1500
# Exactly 1500 bytes
frame.len == 1500
Hostname Filtering
# Specific hostname
http.host == www.tu.ac.th
# Contains keyword
http.host contains "google"
# Multiple hostnames
http.host == www.siit.tu.ac.th || http.host == www.tu.ac.th
Part 4: Analyzing Ping with Wireshark
The Ping Process
When you ping a new IP address (not in ARP cache):
Step-by-Step Sequence:
-
ARP Request (Broadcast)
- Your computer → ALL computers on network
- "Who has IP 192.168.1.50? Tell 192.168.1.100"
- Destination MAC:
ff:ff:ff:ff:ff:ff(broadcast)
-
ARP Reply (Unicast)
- Target computer → Your computer
- "I have 192.168.1.50, my MAC is aa:bb:cc:dd:ee:ff"
- Now your computer knows the MAC address
-
ICMP Echo Request #1
- Your computer → Target
- "Ping!" (Are you there?)
-
ICMP Echo Reply #1
- Target → Your computer
- "Pong!" (Yes, I'm here!)
-
Steps 3-4 repeat for each ping packet
Why ARP Happens First
The Problem:
- You only know the IP address (e.g., 192.168.1.50)
- To send packets on local network, you need the MAC address
- ARP resolves: IP address → MAC address
The Solution:
- Send ARP broadcast asking "Who has this IP?"
- Target replies with its MAC address
- MAC address stored in ARP cache
- ICMP packets can now be sent directly
Analogy: At a party, you want to find "Bob" (IP address) but don't know what he looks like (MAC address). You shout "WHERE'S BOB?" (broadcast ARP). Bob says "I'm Bob, wearing a red shirt!" (ARP reply). Now you can walk directly to Bob (send ICMP).
Analyzing Ping in Wireshark
Setup:
-
Check ARP cache BEFORE ping:
arp -n -
Ping new IP (not in cache):
ping -c 5 192.168.1.50 -
Check ARP cache AFTER ping:
arp -n- IP 192.168.1.50 should now be in cache!
-
Filter in Wireshark:
arp || icmp
Expected Wireshark Output
Packet Sequence:
No. Time Source Destination Protocol Info
1 0.000000 192.168.1.100 Broadcast ARP Who has 192.168.1.50? Tell 192.168.1.100
2 0.001234 192.168.1.50 192.168.1.100 ARP 192.168.1.50 is at aa:bb:cc:dd:ee:ff
3 0.002000 192.168.1.100 192.168.1.50 ICMP Echo (ping) request id=0x1234, seq=1
4 0.003000 192.168.1.50 192.168.1.100 ICMP Echo (ping) reply id=0x1234, seq=1
5 1.002000 192.168.1.100 192.168.1.50 ICMP Echo (ping) request id=0x1234, seq=2
6 1.003000 192.168.1.50 192.168.1.100 ICMP Echo (ping) reply id=0x1234, seq=2
... (continues for 5 packets)
Key Observations:
- Packets 1-2: ARP exchange (only happens once!)
- Packets 3-4: First ping (ICMP echo request/reply)
- Packets 5-6: Second ping
- Pattern: No more ARP after first exchange
Ping to Cached IP (No ARP)
If IP is ALREADY in ARP cache:
# Check cache
arp -n # 192.168.1.50 is already here
# Ping
ping -c 5 192.168.1.50
# Filter
arp || icmpExpected Result:
- NO ARP packets appear
- ONLY ICMP packets visible
- Why? MAC address already known!
Wireshark Output:
No. Time Source Destination Protocol Info
1 0.000000 192.168.1.100 192.168.1.50 ICMP Echo request
2 0.001000 192.168.1.50 192.168.1.100 ICMP Echo reply
3 1.000000 192.168.1.100 192.168.1.50 ICMP Echo request
4 1.001000 192.168.1.50 192.168.1.100 ICMP Echo reply
... (no ARP packets!)
Packet Details Breakdown
ARP Request Packet:
Frame:
- Destination MAC: ff:ff:ff:ff:ff:ff (Broadcast)
- Source MAC: [Your MAC]
Ethernet II:
- Type: ARP (0x0806)
ARP:
- Opcode: Request (1)
- Sender MAC: [Your MAC]
- Sender IP: 192.168.1.100
- Target MAC: 00:00:00:00:00:00
- Target IP: 192.168.1.50
ARP Reply Packet:
Frame:
- Destination MAC: [Your MAC]
- Source MAC: aa:bb:cc:dd:ee:ff
Ethernet II:
- Type: ARP (0x0806)
ARP:
- Opcode: Reply (2)
- Sender MAC: aa:bb:cc:dd:ee:ff
- Sender IP: 192.168.1.50
- Target MAC: [Your MAC]
- Target IP: 192.168.1.100
ICMP Echo Request:
Frame:
- Destination MAC: aa:bb:cc:dd:ee:ff
- Source MAC: [Your MAC]
Ethernet II:
- Type: IPv4 (0x0800)
Internet Protocol:
- Source: 192.168.1.100
- Destination: 192.168.1.50
- Protocol: ICMP (1)
ICMP:
- Type: 8 (Echo request)
- Code: 0
- Identifier: 0x1234
- Sequence: 1
- Data: [56 bytes]
ICMP Echo Reply:
ICMP:
- Type: 0 (Echo reply)
- Code: 0
- Identifier: 0x1234
- Sequence: 1
- Data: [56 bytes]
Protocol Reference
Common Protocols
| Protocol | Layer | Port | Description |
|---|---|---|---|
| ARP | 2 (Data Link) | N/A | Address resolution (IP→MAC) |
| ICMP | 3 (Network) | N/A | Ping, error messages |
| TCP | 4 (Transport) | Various | Reliable, connection-oriented |
| UDP | 4 (Transport) | Various | Unreliable, connectionless |
| HTTP | 7 (Application) | 80 | Web traffic (unencrypted) |
| HTTPS | 7 (Application) | 443 | Web traffic (encrypted) |
| DNS | 7 (Application) | 53 | Domain name resolution |
| SSH | 7 (Application) | 22 | Secure shell |
| FTP | 7 (Application) | 21 | File transfer |
| SMTP | 7 (Application) | 25 | Email sending |
ICMP Types
| Type | Code | Description |
|---|---|---|
| 0 | 0 | Echo Reply (ping response) |
| 3 | - | Destination Unreachable |
| 3 | 0 | Network Unreachable |
| 3 | 1 | Host Unreachable |
| 3 | 3 | Port Unreachable |
| 8 | 0 | Echo Request (ping) |
| 11 | 0 | Time Exceeded (TTL=0) |
TCP Flags
| Flag | Meaning |
|---|---|
[S] | SYN - Synchronize (start connection) |
[.] | ACK - Acknowledgment |
[P] | PSH - Push (send data immediately) |
[F] | FIN - Finish (close connection) |
[R] | RST - Reset (abort connection) |
[S.] | SYN+ACK (handshake response) |