Download practical packet analysis practical packet analysis
Transcript
You can use the forced decode feature multiple times within the same capture file. Because it can be hard to keep track of the forced decodes you have applied when you use more than one in a capture file, Wireshark does this for you. From the Decode As dialog, you can click the Show Current button to display all of the forced decodes you have created so far (see Figure 5-10). You can also clear them by clicking the Clear button. Viewing Dissector Source Code The beauty of working with an open Figure 5-10: Clicking the Show source application is that if you are conCurrent button shows all of the forced fused as to why something is occurring, decodes you have created for a capture file. you can look at the source code and find out the exact reason. This really comes in handy when trying to determine why a particular protocol has been interpreted incorrectly. Examining the source code of protocol dissectors can be done directly from the Wireshark website by hovering over the Develop link and clicking Browse the Code. This link will send you to the Wireshark subversion repository, where you can view the current release code for Wireshark as well as the code for previous releases. Clicking the releases folder will present you with all of the official Wireshark (and even Ethereal) releases, with the newest at the bottom of the list. Once you select the release you want to examine, the protocol dissectors can be found in the epan/dissectors folder. Each dissector is labeled with packets-protocolname.c. These files can be rather complex, but you will find they all follow a standard template and tend to be commented very well. You don’t need to be an expert C programmer to understand the basic function of each dissector. If you want to get a truly deep understanding of what you are seeing in Wireshark, I recommend at least taking a look at dissectors for some of the simpler protocols. Following TCP Streams http_google.pcap 76 Chapter 5 One of Wireshark’s most satisfying analysis features is its ability to reassemble TCP streams into an easily readable format. Rather than viewing data being sent from client to server in a bunch of small chunks, the Follow TCP Stream feature sorts the data to make it easier to view. This comes in handy when viewing plaintext application layer protocols such as HTTP, FTP, and so on. (We’ll take a closer look at how these common protocols work in the next chapter.)