data:image/s3,"s3://crabby-images/69d27/69d278c755df99374b99d95e0fe10b396e636604" alt="Mastering Wireshark 2"
What's new in Wireshark 2?
There's a new version of Wireshark out—a new major version that has many interesting features. Here, you can see the new Qt GUI:
data:image/s3,"s3://crabby-images/60803/6080310d20ac1f7d6597c1e1fc6086c9c8ed493e" alt=""
It looks very similar to the Legacy GTK GUI, with few minor tweaks. The main menu bar here has had some icons changed and removed; the general interface is a little bit cleaner. All the general functionality, though, is all the same. Capture options are on the upper left-hand side and they are denoted by a gear icon. When you click on the gear icon, you have multiple tabs for Input options, Output options, and general Options:
data:image/s3,"s3://crabby-images/eebaf/eebaf0c9215f6db340b53388fd7cc0544430dd5a" alt=""
When you click on Edit | Preferences..., you can see the preferences window, as shown in the following screenshot. Options such as Show up to makes it easy to navigate and view what you need to see:
data:image/s3,"s3://crabby-images/189f9/189f9d54f0630c2ea87a407eb1d31665c92e0758" alt=""
As shown in the following screenshot, on the left-hand side, you can see the related packets diagram show up, based on what you select. So if you select different packets, this will change in size and shape; and what might appear for you is then what you select. This makes it easy to pick out packets that are related to each other without having to follow TCP or UDP streams:
data:image/s3,"s3://crabby-images/d2b38/d2b38acf1d6e0ddda917553e543515726bfe8cbf" alt=""
Under the Statistics menu that is present in the menu bar, many of these statistics options now have a similar-looking window, as shown in the following screenshot. If you look at how the buttons, filters, and general interface is set up, they're all now standardized and look very, very similar to each other, which I'm sure makes coding much easier for those who work on the Wireshark code:
data:image/s3,"s3://crabby-images/17aef/17aef22f7b9e4c60891488cdd01c030e234f7365" alt=""
Click on Statistics | I/O Graph; now you can see the Wireshark IO graph. In the bottom left-hand, you can click on the plus icon and add multiple items to the chart on your IO graph, and you can do this an unlimited number of times:
data:image/s3,"s3://crabby-images/11d46/11d468db754ee755f2b8765d0172fdcc0f7d0b7b" alt=""
Additionally, any changes you make in here are saved to your profile. With this graph, you can also click on Save As... and select different file formats to choose from:
data:image/s3,"s3://crabby-images/49f77/49f77dd2dac0a6746b550a05ea81820b91a843c5" alt=""
Click on Analyze | Follow | UDP Stream; you can see the follow stream dialog box has been updated so that it now allows you to select whether it's the entire conversation or just one side at a time. It also allows you to search for text within:
data:image/s3,"s3://crabby-images/04c0c/04c0c37b0911f89aef2e568c856da845c4ebe4dc" alt=""
In the preceding screenshot you can see the context-aware hints in action. Within this stream, if you look at the bottom, you have some information such as client packets, server packets, and so on, that changes based on what you're hovering over. The main capture window will change to that actual packet.
This is very handy for jumping through the data and being able to see it in relation to the entire capture.
Let's now see how we'll capture traffic and get the first packets in that main window.