Hook
Wireshark: The world's most popular network protocol analyzer
More breakout videos from this creator.
Everybody working in IT or who wants to get into IT needs to understand this networking tool. It's free and it takes like 5 seconds to set it up and get it running. So let's do that right now. It's called Wireshark and it shows you everything that your computer is saying on the network. It lets you see every request, every answer, and every app that's sending your data around in plain text where anybody on the network could read it. And Wireshark has been the industry standard for 20 years. Let me show you how it works. First, go here, download it. Wireshark.org. Once it's open, I'm pressing start. There's like 40,000 lines showing up on this screen, but that's not a problem. We just need to use filters. See this bar here at the top. You just need to type in a filter and press enter. And everything else disappears so you can see what you're actually looking for. Here are the four filters every beginner should learn because these four do most of the work. First one is DNS. Domain Name System. Protocol. Every name your machine looks up, live. This is how you find out what's phoning home. Leave it running for 5 minutes and read the list and I can promise you, you're going to find something you didn't install making DNS queries on the network. Not cool, but at least Wireshark makes you aware of it. Number two, HTTP.request. Press enter. This shows you every web request going out unencrypted. And that's not a good thing. On a modern network, most things are HTTPS. So what shows up here is the stuff that is not HTTPS. So you might find things like old printers and cameras or some smart plug from 2019 or an internal app somebody wrote and forgot about. Next, we have IP.addr and then two equal signs and then type an IP address in. I'm going to put my router in. Now you're just looking at traffic for that one machine or that one device on the network. This is how you're going to eliminate the wall of noise and answer actual questions, which is usually all about one device instead of every device on the network. Number four is a powerful diagnostic tool. TCP.analysis.flags. This one's going to show you retransmissions, duplicates and resets. You'll see where the network is quietly failing and trying over and over again. If you saw my video about that one website that refused to load, this filter would have proved it in about 10 seconds. So there you go. Install it, press start and use these four filters. Save this video for later because one day somebody's going to tell you there's a network problem and you're going to be glad you have this tool set up and ready to go. If you'd like a deeper dive on tools like Wireshark, drop it in the comments and be sure to follow if you like nerdy stuff.