All language subtitles for 12. Wireshark - Basic Overview & How To Use It With MITM Attacks

af Afrikaans
ak Akan
sq Albanian
am Amharic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

And this lecture we're going to talk about a tool called whale shark why a shark is a network protocol

analyzer.

It's not designed for hackers and it's not designed for hacking and spying on other people on the network.

It's designed for network administrators so that they can see what's happening in their network and

make sure that everything is working properly and that nobody is doing anything bad or doing anything

suspicious on the network the way that whale shark works is it allows you to select an interface and

then logs all the packets or all the traffic that flows through that interface.

So you're selecting an interface it could be a wireless card.

It could be a wired card on your on your current computer and then it'll start logging all the information

that flow through that interface.

It also has a really nice graphical interface that allow you to analyze this traffic.

So it allows you to filter these packets based on the protocol using them like HDTV TGP and all that

but also allow you to look for certain things for example if you're looking for cookies or if you're

looking for post or get requests.

And it also allow you to search through these packets it can you can you can search through the information

that's stored in the packets and find the things that you're looking for.

It's a really really big tool and you need a whole course for it.

So in this course we're actually gonna use it in a few lectures just covering the basics or the things

that's related to us so the main idea here is why shark is not a hacking tool it only allows you to

capture the traffic that flows through your own computer through your own interface I'm going to use

it now and it's going to become more clear to you.

So I'm just gonna go to Carly and we're going to start to our shark.

You can run wild shark from the command prompt or you can just go on all applications and type via shark

and it'll show up right here I'm going to click that and that's going to load the program for me.

This is just the normal error.

Just ignore this error and this is the main interface of where shark.

So first of all you can actually just go to the file and go to the open and in here it'll allow you

to open a file that you've already captured so for example if you captured packets using a different

sniffer use an error dump or use in man in the middle left or using teh shark which is the command prompt

part of the shark.

So if you captured packets using any of these programs and you started it in a file you can just come

in here open it and start analyzing that file.

This is really handy because sometimes you don't really want to analyze the traffic on the fly so sometimes

you just want to capture it if you're sometimes you capture it from small laptop or your small capture

and from your phone and you're not even at home you're in somewhere else doing your pen test and then

you go back home and then you want to analyze what you captured then you can still do that in a file

and then just come here go to the file open and open the file that you want to analyze.

So what I want to show you here is the idea that while shark is not a hacking tool it's not going to

capture things happening in a in another device.

It will only capture things that flow through your own interface.

So right here we can see that we have all the interfaces in my computer so we can see that we have 88

0 we have any which is just any and we have all the other ones that some of them are created by virtual

box.

So the main one here is a zero which is the virtual interface connected to my not network and you can

see that there is no traffic flowing through this so you can see that this is constant and nothing's

happened in.

So what I'm going to do now is I'm just gonna make this a little bit smaller and I'm going to open my

browser here and I'm just gonna go to a normal Web site I'm just gonna go to Google dot com

now as you can see right here you can see the traffic 80 heads euro is a spike in up so there was some

traffic generated through 88 0.

So for sniffing on this we'll be able to capture these packets that were sent over 88 0.

Now what I'm gonna do is I'm gonna go through my windows machine just to prove that point and I'm going

to browse the Web site here and you'll see that 88 0 will not be affected and the traffic that's generated

on this Windows machine which is in the same network as the killing machine it will not be captured

by the Cally machine.

So if I just go to Google again here you'll see that nothing happened in 88 0.

So there is no traffic flowing through this.

It's still constant.

And we can only capture packets that go through 88 0.

So now you'll probably ask then why why are sharks so useful why are we even talking about it.

If we can 3D if we can only see things that go through our own computer why are we talking about it.

Well we're talking about it because we see there is a large number of ways that you can become the man

in the middle.

We learned how to do this using a Sharpie spoofing.

And in future lectures I'm gonna show you how to do it by creating a fake access point so when we are

the man in the middle.

If we start sniffing on the interface that's used to become the man in the middle.

We'll be able to capture all the traffic generated by the people that were targeting in our mind in

the middle attack.

So if you if you started the fake access point you can start sniffing on the interface that's broadcasting

the signal and you can capture all the packets sent or received.

To anyone who's connected to that fake access point if you became the man in the middle using a peaceful

spoofing then just select the interface that you used when you launched your IP spoofing attack.

So for now I'm going to become the man in the middle using AARP spoofing.

You can use AARP spoof or Buttercup as I showed you earlier but I'm going to use Buttercup using the

exact same command that we used to do.

So we're literally just doing Buttercup followed by the interface that is connected to my target network

which is 88 0 and I'm launch in my couplet.

The spoof couplet so that it can figures the AARP spoof module and runs it for me to put me in the middle

of the connection so I'm gonna hit enter.

And as you can see it's working as expected.

So right now I should be in the middle of the connection intercepting anything.

The target Windows machine sends or receives.

Now let's go to the Windows machine and see if I do anything here.

If it's going to affect the traffic in 88 0 so we'll see if Fairchild could be able to capture traffic

generated by this computer.

So let's write anything here.

I'm just going to Google or I'm just gonna go to a different Web site I'm just gonna go to Bing

and if we come back here you'll see that we have traffic being generated here and we can see that 88

zero is actually capturing whatever that's happening in a completely different device.

This is happening because when we are the man in the middle all the packets that's generated by the

Windows device has actually been redirected to my own computer right here to the Kali and then wired

shark is sniffing that from the Kali machine sniffing it from my own local machine it's not sniffing

it from the network is not sniffing it from the target computer.

So again if you're doing this with the fake access point then just listen on the interface that you're

broadcasting if you're doing this with a real wireless network if you're connected to your home wireless

network using land zero then you can just do this with land zero but with a peaceful thing you have

to first redirect the traffic then you can use wire shark.

Now this is just to show you what why a shark is and how it works.

And I just wanted to stress the idea that our shark is not a hacking tool.

It's only a program that allows you to log packets flowing through a certain interface and then analyze

these packets.

So in the next video we'll see how we can sniff and analyze packets using wire shark.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.