Re: wireshark - packet sniffing (12352 Views)
Reply
Super Advisor
Piotr Kirklewski
Posts: 339
Registered: ‎01-12-2007
Message 1 of 5 (12,633 Views)

wireshark - packet sniffing

[ Edited ]

Hi there

I'm using Wireshark to capture packets in my network. As it's capturing I'm sending some chat messages using Skype.
Then I'm trying to read those strings from Wireshark: File > Find Packet > String

I can't find any of those strings I was sending via Skype.

Does anyone know why ?

Can I somehow set a trap for Skype messages only ?

Regards

Peter

 

 P.S.This thread has been moved from Insight Remote Support>Security to Security > HP Networking- HP Forums Moderator

Jesus is the King
Please use plain text.
Regular Advisor
Fred K. Abell Jr._1
Posts: 84
Registered: ‎07-23-2004
Message 2 of 5 (12,633 Views)

Re: wireshark - packet sniffing

Peter,

Not going to happen with just wireshark.

Remote-exploit.org talks about it being encrypted, and points to a Black Hat paper http://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-biondi/bh-eu-06-biondi-up.pdf

Do a google search with 'sniff skype' and you will see it is not a trivial exercise.

Fred
Please use plain text.
Regular Advisor
Fred K. Abell Jr._1
Posts: 84
Registered: ‎07-23-2004
Message 3 of 5 (12,633 Views)

Re: wireshark - packet sniffing

Okay, here is an update. This answer requires permission and may be considered hacking. It also may violate wiretapping laws. REALLY REALLY REALLY make sure it is legal and you have permission!!!!!!!

But if you are doing research or testing, you could probably use something like Paros. Paros is a security tool for web application vulnerability assessment. This is a man in the middle type of situation. The skype ssl's to the proxy, and the proxy ssl's onto the destination. The proxy sees everything that goes through.

Please do not use this covertly or illegality.

Fred
Please use plain text.
Occasional Visitor
krepaa
Posts: 1
Registered: ‎02-15-2011
Message 4 of 5 (12,633 Views)

Re: wireshark - packet sniffing

hi there,

i am doing research on siptoskype gateway. i have used astrix for that as the skype communicate with sip only i want to see its Start of Message (SOM) or its frame message or ip header message but could not figure out how i can sneak packet of skype from wireshark,,

any help will be acceptable
Please use plain text.
Occasional Visitor
bspencer63
Posts: 1
Registered: ‎01-25-2011
Message 5 of 5 (12,352 Views)

Re: wireshark - packet sniffing

Piotr,

It's all about filters with Wireshark.  You can run the capture with filters or use filters after the capture is complete to see exactly what you want.  Filter by IP or by protocol. 

 

Check here for Display Filter Reference:  http://www.wireshark.org/docs/dfref/

Check here forHow To Set Up a Capture:  http://wiki.wireshark.org/CaptureSetup

 

The Wireshark book to use and have for ref is: http://www.chappellu.com/wiresharkbook.html

and of course...Laura Chappels blog: http://laurachappell.blogspot.com/

 

Other than that, you may sign up for courses at WiresharkU that are very good.  You can even get an all-access pass that is moderately priced that will allow you to see and attend all online courses for one year.

Good luck and hope this helps!

 

Please use plain text.
The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the Terms of Use and Rules of Participation