Professional Documents
Culture Documents
Presentasi Wireshark
Presentasi Wireshark
By : Budi Isdiyanto
2020-10-30
TRAINING AGENDA
01 What is Wireshark
02 Wireshark Fitures
03 Package Analyzer
(Sniffing)
04 Filter Wireshark
There are several other ways to initiate packet fetching. Select the menu with the
shark fin icon on the left side of the Wireshark toolbar, press Ctrl + E, or double-
click the grid.
Package Analyzer (Sniffing)
Choose File> Save As or choose the Export option to record the capture
Package Analyzer (Sniffing)
To stop capturing, press Ctrl + E. Alternatively, open the Wireshark
toolbar and select the red Stop button located next to the shark fin icon.
Viewing and Analyzing Package Contents
NO PROTOKOL
TIME LENGTH
SOURCE INFO
DESTINATION
List Panel Package (Packet List)
To change the time format to something more useful (like the actual time of
day), choose View> Time Display Format.
Detail Panel Package (Packet Detail)
The detail panel, presents the protocol and protocol fields of the selected
packets in collapsible format. Apart from expanding each option, you can
apply individual Wireshark filters based on specific details and follow the
data flow by protocol type by right-clicking the desired item
Panel Byte Package (Packet Byte)
To display this data in bit format as opposed to hexadecimal, right-
click anywhere in the pane and select as bit.
Wireshark Filter
The capture filter instructs Wireshark to only record packets that meet the
specified criteria. Filters can also be applied to pre-created capture files so
that only certain packets are shown. This is known as a display filter.
put in
Wireshark filter
Over herei
Welcome Screen
Screen Capture
Wireshark Filter
For example, if you want to display only TCP packets, type tcp in the
Wireshark filter
Wireshark Filter
Another way to select a filter is to select a bookmark on the left side of the
entry field. Select Manage Filter Expressions or Manage Display Filters to
add, remove, or edit filters.
1
2
Wireshark Color Rules
While Wireshark's capture and display filters limit which packets are
recorded or displayed on the screen, its coloring function takes it a
step further: It can differentiate between different packet types based
on their individual color. It quickly finds specific packages in the set
stored by their line color in the package list pane.
Wireshark Color Rules
Wireshark comes with around 20 standard coloring rules, each of which can be
edited, disabled, or deleted. Choose View → Coloring Rules for an overview of
what each color means. You can also add your own color based filters.
Choose View→
Colorize Packet
List to turn
packages on and
off.
Wireshark Color Rules
Other useful metrics are available via the Statistics drop-down menu. This
includes size and time information about the capture file, along with dozens of
charts and graphs ranging from packet talk topics to loading HTTP request
distribution.