Un lab pratique sur votre propre machine : installez Wireshark et observez de vrais paquets — la poignée de main et les en-têtes appris — sur votre connexion.
Installer Wireshark localement
LabEn bref
Objectifs
- Installer Wireshark localement
- Capturer et filtrer le trafic en direct
- Trouver une vraie poignée de main TCP dans votre capture
Everything so far has been theory. Now you will see it for real. Wireshark captures the packets crossing your own machine and shows you exactly what you have been reading about — the handshake, the headers, the layers.
Legal
Only ever capture traffic on a network you own or are authorised to monitor. Capturing on a network you do not control may be an offence under Algerian Law 09-04. On your own machine, on your own connection, you are fine.
Install and capture
- Install Wireshark from your package manager or wireshark.org.
- Open it and pick your active interface (usually
wlan0oreth0). - Type
tcp.port == 443in the filter bar and press Enter. - Open a website in your browser and watch the packets appear.
$ sudo apt install wireshark
Setting up wireshark ...
Do you want non-superusers to capture packets? Yes
Tip
You should see a SYN, a SYN-ACK and an ACK at the very start of each new connection. Find one. That is the handshake from the last section, live on your screen.
À retenir
- Wireshark montre les paquets qui traversent votre machine
- Ne capturez que sur des réseaux autorisés
- La théorie devient réelle en voyant la poignée de main en direct