LinuxDays 2024

Your locale preferences have been saved. We like to think that we have excellent support for English in pretalx, but if you encounter issues or errors, please contact us!

Showing Custom Protocols in Wireshark
2024-10-12 , 345
Language: English

We'll extend Wireshark using its Lua API to handle custom protocols.


Maybe you've implemented your own protocol, maybe you bought some strange IoT appliance - you want to analyze network traffic to understand what is going on. Wireshark is just the right tool for that. But there are some protocol it can't know and so you need to extend it.

In this workshop we'll see that it's easy to make Wireshark understand new protocols using its Lua API. We'll start with a simple UDP protocol and see how to deal with TCP's streaming nature.

Prerequisites:
- you should have at least used Wireshark before (no advanced knowledge necessary)


Difficulty

Začátečníci

See also:

I live in Dresden, Germany, where I work as a backend engineer at Staffbase. I speak Czech, German and English, feel free to say hi!