Skip to content
CyberEd DZ

Set Up Wireshark Locally

Lab

In brief

A hands-on lab you build on your own machine: install Wireshark and watch real packets — the handshake and headers you just learned — cross your own connection.

Objectives

  • Install Wireshark locally
  • Capture and filter live traffic
  • Find a real TCP handshake in your own capture

Everything so far has been theory. Now you will see it for real. Wireshark captures the packets crossing your own machine and shows you exactly what you have been reading about — the handshake, the headers, the layers.

Install and capture

  1. Install Wireshark from your package manager or wireshark.org.
  2. Open it and pick your active interface (usually wlan0 or eth0).
  3. Type tcp.port == 443 in the filter bar and press Enter.
  4. Open a website in your browser and watch the packets appear.
$ sudo apt install wireshark
Setting up wireshark ...
Do you want non-superusers to capture packets? Yes

Tip

You should see a SYN, a SYN-ACK and an ACK at the very start of each new connection. Find one. That is the handshake from the last section, live on your screen.

Recap

  • Wireshark shows the packets crossing your machine
  • Only capture on networks you are authorised to
  • The theory becomes real once you see the handshake live