Softpanorama
(slightly skeptical) Open Source Software Educational Society

May the source be with you, but remember the KISS principle ;-)

Softpanorama Search

Wireshark (aka Ethereal)

Old News See also Recommended Books Recommended Links Reference Recommended Papers  
Options Most useful options option -w option_-s Option r    
Filter expressions Expressions primitives Examples Output Format      
ngrep snoop Ethereal Snort Shadow Humor Etc

The name was changed to Wireshark in June, 2006, because creator and lead developer Gerald Combs could not keep using the Ethereal trademark (which was then owned by his old employer, Network Integration Services) when he changed jobs. He still held copyright on most of the source code (and the rest was redistributable under the GNU General Public License), so he took the Subversion repository for Ethereal and used it as the basis for the Subversion repository of Wireshark.

It appears that Ethereal development has ceased, and an Ethereal security advisory recommended switching to Wireshark.

Wireshark - Wikipedia, the free encyclopedia

Wireshark Download

The current stable release of Wireshark is 0.99.5. It supersedes all previous releases, including all releases of Ethereal. You can get it at the following locations:

You will find lots of useful information on the Wireshark homepage at http://www.wireshark.org.

Wiki

The Wireshark Wiki at http://wiki.wireshark.org provides a wide range of information related to Wireshark and packet capturing in general. You will find a lot of information not part of this user's guide. For example, there is an explanation how to capture on a switched network, an ongoing effort to build a protocol reference and a lot more.

An online version is available at the Wireshark website: http://www.wireshark.org/faq.html. You might prefer this online version, as it's typically more up to date and the HTML format is easier to use.

Recommended Links