3 ms·
One really useful tip for Wireshark that's not as obvious as it should be. Increasingly often, what you need to debug is a TLS connection. However, that can ma
by lambda 8y ago
One really useful tip for Wireshark that's not as obvious as it should be.
Increasingly often, what you need to debug is a TLS connection. However, that can make debugging more difficult as the contents of the connection are encrypted.
However, if you can access the server key, whether you have access to the production server, or are working in a development environment, or you MITM yourself with mitmproxy, or you're working on some product that ships the same default server keys with every install, you can load the key into Wireshark and then decrypt all of the TLS traffic.
To do so, go to Preferences > Protocols > SSL, and click "Edit" next to "RSA keys list". Then you can load private keys in, and associate them with a host and port, and when you have a TLS connection on that host and port, Wireshark will decrypt the traffic and you can see the inner protocol.
https://wiki.wireshark.org/SSL https://wiki.wireshark.org/SSL
Note that this doesn't work if you use a cipher suite with forward secrecy, though it looks like there is support for that as well if you enable logging of ephemeral keys in your client or server (https://security.stackexchange.com/questions/35639/decrypting-tls-in-wireshark-when-using-dhe-rsa-ciphersuites/42350#42350 https://security.stackexchange.com/questions/35639/decryptin...)
- rosstex 8y agoThis is supported with Firefox and Chrome. Here's how to set it up: https://jimshaver.net/2015/02/11/decrypting-tls-browser-traffic-with-wireshark-the-easy-way/ https://jimshaver.net/2015/02/11/decrypting-tls-browser-traf...
- deleted 8y ago[deleted]
- lozaning 8y agoAlso if the security model where you work is like where I work and they wont give you the certs, but will allow you to add your own cert, Charles Proxy works a charm. Crazy useful for sending server side errors to mobile apps to simulate failure that otherwise wouldn't be replicable on demand in a production environment.
- plq 8y ago> Crazy useful for sending server side errors to mobile apps to simulate failure That's what test suites are for.
- xorcist 8y agoIf you get a mitmproxy working, you probably won't need the Wireshark bits. Getting ephemeral keys out can be tricky and might not even be worth the trouble. Sometimes I find it convenient to redirect traffic with iptables. That way, if I can classify which traffic interests me, only that traffic will pass through the proxy for inspection. A warning though, SSL specific problems tend to go away when being looked at that way :). A third method I know people use is LD_PRELOADing a hook in the application to dump keys (search for sslkeylog.c for an example) but that's far too exciting for me to try in production. Between these three methods I tend to reach for the proxy first.
- kingosticks 8y agoThere's also a fun example of the third method at [1] which is used to decrypt and dump traffic from the official Spotify app for inspection in wireshark. This is used to reverse engineer their protocol and reimplement it in librespot (and various ports of that). [1] https://github.com/librespot-org/spotify-analyze/blob/master/dump/dump.c https://github.com/librespot-org/spotify-analyze/blob/master...