Aller au contenu
CyberEd DZ

Installer Wireshark localement

Lab

En bref

Un lab pratique sur votre propre machine : installez Wireshark et observez de vrais paquets — la poignée de main et les en-têtes appris — sur votre connexion.

Objectifs

  • Installer Wireshark localement
  • Capturer et filtrer le trafic en direct
  • Trouver une vraie poignée de main TCP dans votre capture

Everything so far has been theory. Now you will see it for real. Wireshark captures the packets crossing your own machine and shows you exactly what you have been reading about — the handshake, the headers, the layers.

Install and capture

  1. Install Wireshark from your package manager or wireshark.org.
  2. Open it and pick your active interface (usually wlan0 or eth0).
  3. Type tcp.port == 443 in the filter bar and press Enter.
  4. Open a website in your browser and watch the packets appear.
$ sudo apt install wireshark
Setting up wireshark ...
Do you want non-superusers to capture packets? Yes

Tip

You should see a SYN, a SYN-ACK and an ACK at the very start of each new connection. Find one. That is the handshake from the last section, live on your screen.

À retenir

  • Wireshark montre les paquets qui traversent votre machine
  • Ne capturez que sur des réseaux autorisés
  • La théorie devient réelle en voyant la poignée de main en direct