目 錄
Preface 序
-
1. Foreword 前言
2. Who should read this document? 誰適合讀該文檔?
3. Acknowledgements 致謝
4. About this document 關於本文檔
5. Where to get the latest copy of this document? 哪里獲取本文檔最新副版
6. Providing feedback about this document 反饋
7. Typographic Conventions 版式約定
1. Introduction 簡介
1.1. What is Wireshark? 什么是Wireshark
-
- 1.1.1. Some intended purposes 預期用途
- 1.1.2. Features 特性
- 1.1.3. Live capture from many different network media 不同網絡介質在線抓取
- 1.1.4. Import files from many other capture programs 導入抓包文件
- 1.1.5. Export files for many other capture programs 導出抓包文件
- 1.1.6. Many protocol dissectors 協議剝離
- 1.1.7. Open Source Software 打開軟件
- 1.1.8. What Wireshark is not
1.2. System Requirements 系統要求
1.3. Where to get Wireshark 如何獲取Wireshark
1.4. A brief history of Wireshark Wireshark簡史
1.5. Development and maintenance of Wireshark Wireshark開發與運維
1.6. Reporting problems and getting help 上報問題並獲得幫助
2. Building and Installing Wireshark 構建安裝Wireshark
2.1. Introduction 簡介
2.2. Obtaining the source and binary distributions 獲取源碼和二進制發行版
2.3. Installing Wireshark under Windows Windows安裝Wireshark
-
- 2.3.1. Installation Components 安裝組件
- 2.3.2. Additional Tasks 額外任務
- 2.3.3. Install Location 安裝位置
- 2.3.4. Installing Npcap 安裝Npcap
- 2.3.5. Windows installer command line options Windows安裝命令行選項
- 2.3.6. Manual Npcap Installation 手動Npcap安裝
- 2.3.7. Update Wireshark 升級Wireshark
- 2.3.8. Update Npcap 升級Npcap
- 2.3.9. Uninstall Wireshark 協助Wireshark
- 2.3.10. Uninstall Npcap 協助Npcap
2.4. Installing Wireshark under macOS macOS安裝Wireshark
2.5. Building Wireshark from source under UNIX UNIX源碼安裝Wireshark
2.6. Installing the binaries under UNIX UNIX二進制安裝Wireshark
-
- 2.6.1. Installing from RPMs under Red Hat and alike 紅帽環境下RPM安裝
- 2.6.2. Installing from debs under Debian, Ubuntu and other Debian derivatives Debian等環境deb安裝
- 2.6.3. Installing from portage under Gentoo Linux GentooLinux環境 portage安裝
- 2.6.4. Installing from packages under FreeBSD FreeBSD環境安裝包安裝
2.7. Troubleshooting during the build and install on Unix Unix構建安裝問題快照
2.8. Building from source under Windows Windows下源碼安裝
3. User Interface 用戶界面
3.1. Introduction 簡介
3.2. Start Wireshark 啟動Wireshark
3.3. The Main window 主界面
3.4. The Menu 菜單
3.5. The “File” menu 菜單-文件
3.6. The “Edit” Menu 菜單-編輯
3.7. The “View” Menu 菜單-視圖
3.8. The “Go” Menu 菜單-跳轉
3.9. The “Capture” menu 菜單-捕獲
3.10. The “Analyze” Menu 菜單-分析
3.11. The “Statistics” Menu 菜單-統計
3.12. The “Telephony” Menu 菜單-電話
3.13. The “Tools” Menu 菜單-工具
3.14. The “Help” Menu 菜單-幫助
3.15. The “Main” Toolbar 工具欄-常規工具
3.16. The “Filter” Toolbar 工具欄-過濾
3.17. The “Packet List” Pane 面板-報文列表
3.18. The “Packet Details” Pane 面板-報文詳情
3.19. The “Packet Bytes” Pane 面板-報文字節
3.20. The Statusbar 狀態欄
4. Capturing Live Network Data 捕獲在線網絡數據
4.1. Introduction 簡介
4.2. Prerequisites 前提條件
4.3. Start Capturing 開始捕獲
4.4. The “Capture Interfaces” dialog box 捕獲界面對話框
4.5. The “Capture Options” dialog box 捕獲設置對話框
4.6. The “Edit Interface Settings” dialog box 編輯界面設置對話框
4.7. The “Compile Results” dialog box 編譯結果對話框
4.8. The “Add New Interfaces” dialog box 增加新接口對話框
-
- 4.8.1. Add or remove pipes 新增/刪除?
- 4.8.2. Add or hide local interfaces 新增/隱藏本地接口
- 4.8.3. Add or hide remote interfaces 新增/隱藏遠方接口
4.9. The “Remote Capture Interfaces” dialog box 遠程捕獲接口對話框
4.10. The “Interface Details” dialog box 接口詳情對話框
4.11. Capture files and file modes 捕獲文件及文件模式
4.12. Link-layer header type 鏈接層頭類型
4.13. Filtering while capturing 抓包時過濾
4.14. While a Capture is running … 抓包過程中
5. File Input, Output, and Printing 文件輸入、輸出、打印
5.1. Introduction 簡介
5.2. Open capture files 打開抓包文件
5.3. Saving captured packets 保存抓包
5.4. Merging capture files 合並抓包
5.5. Import hex dump 導入 hex dump
5.6. File Sets 文件設置
5.7. Exporting data 導出數據
-
- 5.7.1. The “Export as Plain Text File” dialog box
- 5.7.2. The “Export as PostScript File” dialog box
- 5.7.3. The “Export as CSV (Comma Separated Values) File” dialog box
- 5.7.4. The “Export as C Arrays (packet bytes) file” dialog box
- 5.7.5. The “Export as PSML File” dialog box
- 5.7.6. The “Export as PDML File” dialog box
- 5.7.7. The “Export selected packet bytes” dialog box
- 5.7.8. The “Export Objects” dialog box
5.8. Printing packets 打印包
5.9. The “Packet Range” frame 包范圍?
5.10. The Packet Format frame 包模式?
6. Working With Captured Packets 抓包文件用途
6.1. Viewing Packets You Have Captured 查看抓包文件
6.2. Pop-up Menus 彈出式菜單
-
- 6.2.1. Pop-up Menu Of The “Packet List” Column Header 報文列表列標題彈出菜單
- 6.2.2. Pop-up Menu Of The “Packet List” Pane 報文列表面包彈出菜單
- 6.2.3. Pop-up Menu Of The “Packet Details” Pane 報文詳情面板彈出菜單
- 6.2.4. Pop-up Menu Of The “Packet Bytes” Pane 報文字節面板彈出菜單