Download practical packet analysis practical packet analysis

Transcript
You can use the forced decode
feature multiple times within the same
capture file. Because it can be hard to
keep track of the forced decodes you have
applied when you use more than one in a
capture file, Wireshark does this for you.
From the Decode As dialog, you can click
the Show Current button to display all
of the forced decodes you have created
so far (see Figure 5-10). You can also clear
them by clicking the Clear button.
Viewing Dissector Source Code
The beauty of working with an open
Figure 5-10: Clicking the Show
source application is that if you are conCurrent button shows all of the forced
fused as to why something is occurring,
decodes you have created for a capture file.
you can look at the source code and find
out the exact reason. This really comes in
handy when trying to determine why a
particular protocol has been interpreted
incorrectly.
Examining the source code of protocol dissectors can be done directly
from the Wireshark website by hovering over the Develop link and clicking
Browse the Code. This link will send you to the Wireshark subversion repository, where you can view the current release code for Wireshark as well as the
code for previous releases. Clicking the releases folder will present you with all
of the official Wireshark (and even Ethereal) releases, with the newest at the
bottom of the list. Once you select the release you want to examine, the protocol dissectors can be found in the epan/dissectors folder. Each dissector is
labeled with packets-protocolname.c.
These files can be rather complex, but you will find they all follow a
standard template and tend to be commented very well. You don’t need to
be an expert C programmer to understand the basic function of each dissector. If you want to get a truly deep understanding of what you are seeing in
Wireshark, I recommend at least taking a look at dissectors for some of the
simpler protocols.
Following TCP Streams
http_google.pcap
76
Chapter 5
One of Wireshark’s most satisfying analysis features is its ability to reassemble
TCP streams into an easily readable format. Rather than viewing data being
sent from client to server in a bunch of small chunks, the Follow TCP Stream
feature sorts the data to make it easier to view. This comes in handy when
viewing plaintext application layer protocols such as HTTP, FTP, and so on.
(We’ll take a closer look at how these common protocols work in the next
chapter.)