5 ms·
Pop Quiz: Who remembers Wireshark’s original name? What a fun tool for over two decades!
by kingforaday 5y ago
Pop Quiz: Who remembers Wireshark’s original name?
What a fun tool for over two decades!
- ziml77 5y agoEthereal. But I thought it was pronounced Ether Real. I'm not sure I'd encountered the word ethereal in any other context at that point (pre-teen/young teen).
- bsedlm 5y agoethersomething??
- cookiengineer 5y ago> Pop Quiz: Who remembers Wireshark’s original name? That's a real question for the ethernet people ;)
- pieter_mj 5y agoHehe, I've never used it when it was called ethereal.
- kingforaday 5y agoLove it! :)
- maze-le 5y agoI still remember how flashed I was seeing the byte-by-byte analysis of a network package for the first time -- it was a real eye opening moment for me.
- qiskit 5y agoHate to be that guy, but network packet. But yeah, it's quite the revelation especially when you realize other people can also sniff the network and capture the unencrypted traffic. Remember thinking nobody would waste so much time and energy. How young and naive I was back then.
- tssva 5y agoHate to be that guy, but Wireshark captures and decodes protocols starting at the data layer. So in the most common case what you see is the decode of the ethernet frame which in the majority of cases but not all includes a network packet inside it which Wireshark further decodes. If you were capturing from an ATM network you would see ATM cells being decoded. For some protocols the data layer unit is also referred to as a packet in which case you would see the data layer packet which includes the network packet. But yeah, it is pretty cool no matter what you want to call things.
- yardstick 5y agoI believe the parent was pointing out a typo, package should have been parent. I don’t think he was saying that it only has capabilities from the network layer onwards.
- gelstudios 5y agoThe original domain name is crypto bait now. Wireshark and its predecessors have made it easy to visualize how protocols actually work, and peel back the magic that makes the internet work. Between the ability to "follow TCP stream" or the "conversation" views between two hosts, wireshark has helped connect the abstract and the observed / real behavior of networks. Which seems to make the difference for people trying to get beyond the basics of networking in workshops / training sessions. The built-in protocol dissectors are also a big help for teaching. Some common situations won't work well out of the box (multi interface PCAPs), or I need to read the manual again... but with a bit of scripting / light processing of the PCAP it works very well.
- khimaros 5y agoalso very useful for reverse engineering devices using a custom protocol over USB bulk data (in conjunction with a Windows/OSX VM and the usbmon kernel module).
- mistrial9 5y agodude- wireshark was the name from a really, really long time ago.. that is real trivia
- cortesoft 5y agoWhether it was a "really, really" long time ago or not is dependent on how old you are.
- tssva 5y agoI remember replacing Novell LANalyzer for Windows with Ethereal, so it doesn't seem that long ago to me. Of course I also remember replacing The Sniffer from Network General which ran under DOS with LANalyzer for Windows.
- seba_dos1 5y agoInitially I dismissed this comment as I remember it changing name and I'm still in my twenties, but it turns out that it got renamed the same year I actually switched to GNU/Linux, so I was very close to missing the original name :)
- Existenceblinks 5y agoRight after TCP/IP class around 2009, I haven't touched it since. Zero gas Ethereal!?
- astura 5y agoEthereal. I was working a job where I had to use it daily when they changed the name to Wireshark. Around 2006-2007 IIRC. I never got used to the new name and left that job shortly afterwards. Wireshark is an objectively better name though, it's for the best.
- vocram 5y agoBut real “hackers” used Ettercap instead!
- nonrandomstring 5y agoReal hackers use tshark :) [1] I try to get my students doing everything from commandline, creating pcap files. When they finally see the GUI of Wireshark they think they died and went to heaven. [1] It's actually the capture part of Wireshark
- geraldcombs 5y agoApologies for "well, actually"-ing here, but the capture part of Wireshark is dumpcap and the various extcap utilities (sshdump, ciscodump, etc). TShark is the command line interface to Wireshark's dissection engine, which, as you point out can be a really useful thing to have. It ships with a bunch of other command line utilities as well, such as editcap, mergecap, and capinfos: https://www.wireshark.org/docs/man-pages/ https://www.wireshark.org/docs/man-pages/
- nonrandomstring 5y ago> sshdump Thanks for that handy one I'd missed until now!
- Agentlien 5y agoI still call it Ethereal sometimes. For some reason the name change really confused me and it took ages to get used to the new name. It's a wonderful tool and I'm very happy our network technology teacher showed us this back in high school.