4 ms·
I've never used wireshark, but fwiw it's trivial to filter by destination with, for example, tcpdump.
by startling 10y ago
I've never used wireshark, but fwiw it's trivial to filter by destination with, for example, tcpdump.
- tehwalrus 10y agoWireshark's display filters are much nicer than tcpdump's BPF; a much simpler language definition.
- bahjoite 10y agoKnown as "capture filters" in Wireshark and as easy as: "host www.afterthedeadline.com".
- userbinator 10y agoThe problem isn't filtering but determining what to look for - a lot of these are hosted on things like AWS or some CDN, which means machines with very generic hostnames, and you'd have to catch a meaningful DNS lookup to get started. If the traffic is encrypted, you still have no great idea what's actually being sent (is it fragments of the file you're working on, which keys you've pressed in the last 10 secons, or an automatic update check? They could all be similar sizes), and if the application is doing security "correctly" it will be very hard to MITM.
- startling 10y agoIt's actually pretty easy to mitm your own https with tools like mitmproxy: https://mitmproxy.org/ https://mitmproxy.org/ But in this case getting the application to use the proxy may have been tricky.