There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash driver drivers error ethernet excel freeze gaming google gpu graphics hard drive hardware hdmi internet laptop malware memory monitor motherboard mouse network printer problem ram registry router server slow software sound svchost.exe trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Wireshark 1.2.2 - how secure is it?

Reply  
Thread Tools
BlackHorseman's Avatar
Member with 451 posts.
 
Join Date: Apr 2002
21-Oct-2009, 08:34 PM #1
Wireshark 1.2.2 - how secure is it?
Hi,

Well, this is a general question: I've read that, though Wireshark is considered to be maybe the best packet sniffer out there, it used to have some serious security holes. Ones that could be utilized by hackers to gain control of your machine.

Two questions before I start using it:

1) Is this still the case?
2) If I install it, will the security breaches supposedly introduced by Wireshark be present in my system even when I don't run it?

Thanks,
Daniel.
__________________
No animals were harmed in the making of this steak
TOGG's Avatar
Distinguished Member with 5,362 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
22-Oct-2009, 05:20 PM #2
According to the release notes 1.2.2 fixed three issues; http://www.wireshark.org/security/wnpa-sec-2009-06.html
wgman21's Avatar
Computer Specs
Member with 104 posts.
 
Join Date: Dec 2008
Experience: Intermediate
22-Oct-2009, 06:50 PM #3
WTH is a packet sniffer?
TOGG's Avatar
Distinguished Member with 5,362 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
23-Oct-2009, 01:39 PM #4
Software to 'sniff' (or check or test) the content of packets of data passing over a network I think (I didn't check Wikipedia, so that could be completely wrong!).

I only knew about Wireshark because I visit the Internet Storm Center at a site called SANS.org, which is maintained by and for network admins and most of it goes over my head. However, it does occasionally have info of interest to a general home user like myself (such as early warning of the next major exploit).

Here's the Wireshark story as it appeared at Sans org; http://isc.sans.org/diary.html?storyid=7132
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
BlackHorseman's Avatar
Member with 451 posts.
 
Join Date: Apr 2002
28-Oct-2009, 07:52 AM #5
As I understand it, all information transferred through the Internet is packed in packets. What Wireshark (and any other packet sniffer) does is read and analyze those packages, without stopping them from reaching their destination. However, in order to do that it requires access to sensitive OS areas, which means that if it has security vulnerabilities/holes, they could be used to do some damage to your system.

TOGG - yeah, I've read the R-notes. But it discusses some specific fixes they've made, doesn't really tell you how secure (or not) it is now.
__________________
No animals were harmed in the making of this steak
lotuseclat79's Avatar
Distinguished Member with 21,345 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
28-Oct-2009, 10:32 AM #6
Hi BlackHorseman,

Here's a Security excerpt from Wireshark:

Quote:
One possible alternative is to run tcpdump, or the dumpcap utility that comes with Wireshark, with superuser privileges to capture packets into a file, and later analyze these packets by running Wireshark with restricted privileges on the packet capture dump file. On wireless networks, it is possible to use the Aircrack wireless security tools to capture IEEE 802.11 frames and read the resulting dump files with Wireshark.

As of Wireshark 0.99.7, Wireshark and tshark run dumpcap to do traffic capture. On platforms where special privileges are needed to capture traffic, only dumpcap needs to be set up to run with those special privileges - neither Wireshark nor tshark need to run with special privileges, and neither of them should be run with special privileges.
As an aside, I would only run Wireshark as advised above, and then only to inspect an internal network. The latest stable version is 1.2.3 / 2009-10-27.

-- Tom
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 06:19 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.