Wireshark tricks
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)
Improve your Wireshark skills
Tutorials
ŠŠ°ŃŃŃŠæŠ½Ń Š½Š°Š²ŃŠ°Š»ŃŠ½Ń ŠæŠ¾ŃŃŠ±Š½ŠøŠŗŠø ŃŃŠ“Š¾Š²Š¾ ŠæŃŠ“Ń Š¾Š“ŃŃŃ Š“Š»Ń Š²ŠøŠ²ŃŠµŠ½Š½Ń Š“ŠµŃŠŗŠøŃ Š¾ŃŠ½Š¾Š²Š½ŠøŃ ŃŃŃŠŗŃŠ²:
Analysed Information
Expert Information
ŠŠ»Š°ŃŠ½ŃŠ²ŃŠø Š½Š° Analyze --> Expert Information, Š²Šø Š¾ŃŃŠøŠ¼Š°ŃŃŠµ Š¾Š³Š»ŃŠ“ ŃŠ¾Š³Š¾, ŃŠ¾ Š²ŃŠ“Š±ŃŠ²Š°ŃŃŃŃŃ Š² Š°Š½Š°Š»ŃŠ·Š¾Š²Š°Š½ŠøŃ ŠæŠ°ŠŗŠµŃŠ°Ń :
Resolved Addresses
Š£ Statistics --> Resolved Addresses Š²Šø Š¼Š¾Š¶ŠµŃŠµ Š·Š½Š°Š¹ŃŠø ŠŗŃŠ»ŃŠŗŠ° ŃŠ½ŃŠ¾ŃŠ¼Š°ŃŃŃ, ŃŠŗŠ° Š±ŃŠ»Š° "ŃŠ¾Š·Š²'ŃŠ·Š°Š½Š°" Wireshark, Š½Š°ŠæŃŠøŠŗŠ»Š°Š“, ŠæŠ¾ŃŃ/ŃŃŠ°Š½ŃŠæŠ¾ŃŃ Š“Š¾ ŠæŃŠ¾ŃŠ¾ŠŗŠ¾Š»Ń, MAC Š“Š¾ Š²ŠøŃŠ¾Š±Š½ŠøŠŗŠ° ŃŠ¾ŃŠ¾. Š¦ŃŠŗŠ°Š²Š¾ Š·Š½Š°ŃŠø, ŃŠ¾ Š·Š°Š»ŃŃŠµŠ½Š¾ Š² ŠŗŠ¾Š¼ŃŠ½ŃŠŗŠ°ŃŃŃ.
Protocol Hierarchy
Š£ Statistics --> Protocol Hierarchy Š²Šø Š¼Š¾Š¶ŠµŃŠµ Š·Š½Š°Š¹ŃŠø ŠæŃŠ¾ŃŠ¾ŠŗŠ¾Š»Šø, Š·Š°Š»ŃŃŠµŠ½Ń Š² ŠŗŠ¾Š¼ŃŠ½ŃŠŗŠ°ŃŃŃ, ŃŠ° Š“Š°Š½Ń ŠæŃŠ¾ Š½ŠøŃ .
Conversations
Š£ Statistics --> Conversations Š²Šø Š¼Š¾Š¶ŠµŃŠµ Š·Š½Š°Š¹ŃŠø ŃŠµŠ·ŃŠ¼Šµ ŃŠ¾Š·Š¼Š¾Š² Ń ŠŗŠ¾Š¼ŃŠ½ŃŠŗŠ°ŃŃŃ ŃŠ° Š“Š°Š½Ń ŠæŃŠ¾ Š½ŠøŃ .
Endpoints
Š£ Statistics --> Endpoints Š²Šø Š¼Š¾Š¶ŠµŃŠµ Š·Š½Š°Š¹ŃŠø ŃŠµŠ·ŃŠ¼Šµ ŠŗŃŠ½ŃŠµŠ²ŠøŃ ŃŠ¾ŃŠ¾Šŗ Ń ŠŗŠ¾Š¼ŃŠ½ŃŠŗŠ°ŃŃŃ ŃŠ° Š“Š°Š½Ń ŠæŃŠ¾ ŠŗŠ¾Š¶Š½Ń Š· Š½ŠøŃ .
DNS info
Š£ Statistics --> DNS Š²Šø Š¼Š¾Š¶ŠµŃŠµ Š·Š½Š°Š¹ŃŠø ŃŃŠ°ŃŠøŃŃŠøŠŗŃ ŠæŃŠ¾ Š·Š°Ń Š¾ŠæŠ»ŠµŠ½Ń DNS Š·Š°ŠæŠøŃŠø.
I/O Graph
Š£ Statistics --> I/O Graph Š²Šø Š¼Š¾Š¶ŠµŃŠµ Š·Š½Š°Š¹ŃŠø Š³ŃŠ°ŃŃŠŗ ŠŗŠ¾Š¼ŃŠ½ŃŠŗŠ°ŃŃŃ.
Filters
Š¢ŃŃ Š²Šø Š¼Š¾Š¶ŠµŃŠµ Š·Š½Š°Š¹ŃŠø ŃŃŠ»ŃŃŃŠø Wireshark Š² Š·Š°Š»ŠµŠ¶Š½Š¾ŃŃŃ Š²ŃŠ“ ŠæŃŠ¾ŃŠ¾ŠŗŠ¾Š»Ń: https://www.wireshark.org/docs/dfref/ ŠŠ½ŃŃ ŃŃŠŗŠ°Š²Ń ŃŃŠ»ŃŃŃŠø:
(http.request or ssl.handshake.type == 1) and !(udp.port eq 1900)
HTTP ŃŠ° ŠæŠ¾ŃŠ°ŃŠŗŠ¾Š²ŠøŠ¹ HTTPS ŃŃŠ°ŃŃŠŗ
(http.request or ssl.handshake.type == 1 or tcp.flags eq 0x0002) and !(udp.port eq 1900)
HTTP ŃŠ° ŠæŠ¾ŃŠ°ŃŠŗŠ¾Š²ŠøŠ¹ HTTPS ŃŃŠ°ŃŃŠŗ + TCP SYN
(http.request or ssl.handshake.type == 1 or tcp.flags eq 0x0002 or dns) and !(udp.port eq 1900)
HTTP ŃŠ° ŠæŠ¾ŃŠ°ŃŠŗŠ¾Š²ŠøŠ¹ HTTPS ŃŃŠ°ŃŃŠŗ + TCP SYN + DNS Š·Š°ŠæŠøŃŠø
Search
ŠÆŠŗŃŠ¾ Š²Šø Ń Š¾ŃŠµŃŠµ ŃŃŠŗŠ°ŃŠø Š²Š¼ŃŃŃ Š²ŃŠµŃŠµŠ“ŠøŠ½Ń ŠæŠ°ŠŗŠµŃŃŠ² ŃŠµŃŃŠ¹, Š½Š°ŃŠøŃŠ½ŃŃŃ CTRL+f. ŠŠø Š¼Š¾Š¶ŠµŃŠµ Š“Š¾Š“Š°ŃŠø Š½Š¾Š²Ń ŃŠ°ŃŠø Š“Š¾ Š¾ŃŠ½Š¾Š²Š½Š¾Ń ŃŠ½ŃŠ¾ŃŠ¼Š°ŃŃŠ¹Š½Š¾Ń ŠæŠ°Š½ŠµŠ»Ń (No., Time, Source ŃŠ¾ŃŠ¾), Š½Š°ŃŠøŃŠ½ŃŠ²ŃŠø ŠæŃŠ°Š²Ń ŠŗŠ½Š¾ŠæŠŗŃ Š¼ŠøŃŃ, Š° ŠæŠ¾ŃŃŠ¼ ŃŠµŠ“Š°Š³ŃŃŃŠø ŃŃŠ¾Š²ŠæŠµŃŃ.
Free pcap labs
ŠŃŠ°ŠŗŃŠøŠŗŃŠ¹ŃŠµŃŃ Š· Š±ŠµŠ·ŠŗŠ¾ŃŃŠ¾Š²Š½ŠøŠ¼Šø Š²ŠøŠŗŠ»ŠøŠŗŠ°Š¼Šø Š½Š°: https://www.malware-traffic-analysis.net/
Identifying Domains
ŠŠø Š¼Š¾Š¶ŠµŃŠµ Š“Š¾Š“Š°ŃŠø ŃŃŠ¾Š²ŠæŠµŃŃ, ŃŠŗŠøŠ¹ ŠæŠ¾ŠŗŠ°Š·ŃŃ Š·Š°Š³Š¾Š»Š¾Š²Š¾Šŗ Host HTTP:
Š ŃŃŠ¾Š²ŠæŠµŃŃ, ŃŠŗŠøŠ¹ Š“Š¾Š“Š°Ń ŃŠ¼'Ń ŃŠµŃŠ²ŠµŃŠ° Š· ŃŠ½ŃŃŃŃŃŃŠ¾Š³Š¾ HTTPS Š·'ŃŠ“Š½Š°Š½Š½Ń (ssl.handshake.type == 1):
Identifying local hostnames
From DHCP
Š£ ŃŃŃŠ°ŃŠ½Š¾Š¼Ń Wireshark Š·Š°Š¼ŃŃŃŃ bootp
Š²Š°Š¼ ŠæŠ¾ŃŃŃŠ±Š½Š¾ ŃŃŠŗŠ°ŃŠø DHCP
From NBNS
Decrypting TLS
Decrypting https traffic with server private key
edit>preference>protocol>ssl>
ŠŠ°ŃŠøŃŠ½ŃŃŃ Edit Ń Š“Š¾Š“Š°Š¹ŃŠµ Š²ŃŃ Š“Š°Š½Ń ŃŠµŃŠ²ŠµŃŠ° ŃŠ° ŠæŃŠøŠ²Š°ŃŠ½ŠøŠ¹ ŠŗŠ»ŃŃ (IP, Port, Protocol, Key file and password)
Decrypting https traffic with symmetric session keys
ŠÆŠŗ Firefox, ŃŠ°Šŗ Ń Chrome Š¼Š°ŃŃŃ Š¼Š¾Š¶Š»ŠøŠ²ŃŃŃŃ Š·Š°ŠæŠøŃŃŠ²Š°ŃŠø TLS ŃŠµŃŃŠ¹Š½Ń ŠŗŠ»ŃŃŃ, ŃŠŗŃ Š¼Š¾Š¶Š½Š° Š²ŠøŠŗŠ¾ŃŠøŃŃŠ¾Š²ŃŠ²Š°ŃŠø Š· Wireshark Š“Š»Ń ŃŠ¾Š·ŃŠøŃŃŠ¾Š²ŠŗŠø TLS ŃŃŠ°ŃŃŠŗŃ. Š¦Šµ Š“Š¾Š·Š²Š¾Š»ŃŃ ŠæŃŠ¾Š²Š¾Š“ŠøŃŠø Š“ŠµŃŠ°Š»ŃŠ½ŠøŠ¹ Š°Š½Š°Š»ŃŠ· Š·Š°Ń ŠøŃŠµŠ½ŠøŃ ŠŗŠ¾Š¼ŃŠ½ŃŠŗŠ°ŃŃŠ¹. ŠŃŠ»ŃŃŠµ Š“ŠµŃŠ°Š»ŠµŠ¹ ŠæŃŠ¾ ŃŠµ, ŃŠŗ Š²ŠøŠŗŠ¾Š½Š°ŃŠø ŃŠµ ŃŠ¾Š·ŃŠøŃŃŃŠ²Š°Š½Š½Ń, Š¼Š¾Š¶Š½Š° Š·Š½Š°Š¹ŃŠø Š² ŠæŠ¾ŃŃŠ±Š½ŠøŠŗŃ Š½Š° Red Flag Security.
Š©Š¾Š± Š²ŠøŃŠ²ŠøŃŠø ŃŠµ, ŃŃŠŗŠ°Š¹ŃŠµ Š² ŃŠµŃŠµŠ“Š¾Š²ŠøŃŃ Š·Š¼ŃŠ½Š½Ń SSLKEYLOGFILE
Š¤Š°Š¹Š» ŃŠæŃŠ»ŃŠ½ŠøŃ ŠŗŠ»ŃŃŃŠ² Š²ŠøŠ³Š»ŃŠ“Š°ŃŠøŠ¼Šµ ŃŠ°Šŗ:
Š©Š¾Š± ŃŠ¼ŠæŠ¾ŃŃŃŠ²Š°ŃŠø ŃŠµ Š² Wireshark, ŠæŠµŃŠµŠ¹Š“ŃŃŃ Š“Š¾ _edit > preference > protocol > ssl > Ń ŃŠ¼ŠæŠ¾ŃŃŃŠ¹ŃŠµ Š¹Š¾Š³Š¾ Š² (Pre)-Master-Secret log filename:
ADB communication
ŠŠøŃŃŠ³Š½ŃŃŃ APK Š· ADB ŠŗŠ¾Š¼ŃŠ½ŃŠŗŠ°ŃŃŃ, Š“Šµ APK Š±ŃŠ² Š½Š°Š“ŃŃŠ»Š°Š½ŠøŠ¹:
ŠŠøŠ²ŃŠ°Š¹ŃŠµ ŃŠ° ŠæŃŠ°ŠŗŃŠøŠŗŃŠ¹ŃŠµ AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) ŠŠøŠ²ŃŠ°Š¹ŃŠµ ŃŠ° ŠæŃŠ°ŠŗŃŠøŠŗŃŠ¹ŃŠµ GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)
Last updated