Wireshark Tutorial for Beginners | Network Scanning Made Easy

Поділитися
Вставка
  • Опубліковано 5 лют 2025

КОМЕНТАРІ • 199

  • @AnsonAlexander
    @AnsonAlexander  Рік тому +138

    CORRECTION: At 11:45 HTTPS traffic goes on port 443, not 80. The correct filter is: "tcp.port==443". Port 80 is usually HTTP traffic. Sorry, had a lot going on in this one!

    • @BettyDuBois
      @BettyDuBois Рік тому +9

      You were looking at compressed (gzip) data. That's why it looks like encrypted data.

    • @edwinfrancisco8116
      @edwinfrancisco8116 Рік тому +18

      @@BettyDuBois This clarified my confusion. I was wondering why the HTTP packets were encrypted. I was starting to doubt my knowledge of computer networking, haha

    • @mikkio5371
      @mikkio5371 11 місяців тому +4

      Yea I was waiting to hear 443 . But thanks .

    • @bazejczuk8972
      @bazejczuk8972 8 місяців тому

      😅

    • @bazejczuk8972
      @bazejczuk8972 8 місяців тому +2

      It is always possible to not know or forget something. Don't worry, you're doing a good job!

  • @sbutler888
    @sbutler888 Рік тому +25

    You've got an absolutely amazing ability to explain things quickly and clearly. I tend to get bored and distracted when I visit UA-camr videos explaining topics like these so I quickly jump to something else. People can talk so slow and repeat themselves so many times, I get antsy to hear what's next. I'm learning a lot from your video. I just downloaded Wireshark yesterday. I graduated over 30 years ago with a BSEE and haven't written ANY code for well over 20 years. I've been able to pick up enough to start troubleshooting the massive data consumption issue I'm having on my plan. Consumption has more than doubled in one month with only 2 of us in our home. I can now identify which device is consuming the largest amount of data at any given time. WOO HOO!! Still waiting for Comcast to call me after multiple calls and Agent Chats. I hope to figure out my issue myself with help from providers like you! THANK YOU!!

    • @littop0
      @littop0 6 місяців тому

      @@yeayea8334 it's meant for beginners

  • @kayanowtoo7593
    @kayanowtoo7593 26 днів тому +7

    Old man in my 70's recently hacked trying to get to grips with all this stuff. It's a nightmare journey but you have seriously eased the way. Many thanks.

    • @aty4282
      @aty4282 3 дні тому +1

      Im 22 and barely understand theese things so id say you're doing great gramps

  • @CameronCollege-i3p
    @CameronCollege-i3p Рік тому +11

    Where was this when I was in university, that actually sums up more than I learned on how to use wireshark in my first semester.

    • @jerrybeans3829
      @jerrybeans3829 26 днів тому

      Yo fr don’t lie I’m studying that rn

    • @Lilkevtalk
      @Lilkevtalk День тому

      Dawg I’m fresh out university . I went for business after fiddling around with Kali vm and firewalls I ran into wire shark and now I’m capturing packets for fun 😂 it’s only been a month

  • @collectorscloset813
    @collectorscloset813 Рік тому +9

    Seriously the most useful video on this thanks

  • @loadoutlab1
    @loadoutlab1 Рік тому +6

    Amazing video. Very clear and to the point! Subscribed!

  • @hadestech8147
    @hadestech8147 Рік тому +4

    Anson, outstanding fast simple straight forward. Thanks

  • @edwinfrancisco8116
    @edwinfrancisco8116 Рік тому +8

    I have been watching videos on the topic of Wireshark. Your video blew all of those videos out of the water! Your step-by-step examples and tips were so helpful! I also really like how your video was straight to the point! THANK YOU!!

  • @ipaemer2604
    @ipaemer2604 Рік тому +3

    Very helpful and great video! I would also like to watch more videos about wireshark, to learn more. Excellent work!

  • @CD-ch8ex
    @CD-ch8ex 2 місяці тому

    Studying at university and this video is a job well done!
    Lot of time saved.
    A very good starting point.
    Also appreciate the part where you go a little further like the security key to decrypt what's in encrypted protocols.
    I'll for sure check your other videos.
    Continue your great work.

  • @eechaze12
    @eechaze12 Рік тому +5

    Thanks for this tutorial. I'm new to using Wireshark

  • @LukasKopca
    @LukasKopca 3 місяці тому +1

    Díky!

  • @eulisestovar92
    @eulisestovar92 2 дні тому

    Good stuff man. I’m gonna have to do some investigating tomorrow on some weird network issues and this was a good refresh for an amateur network admin

  • @johnrieley1404
    @johnrieley1404 Рік тому

    Thanks much for clear teaching and nice graphics. Just studying my ham radio UDP multicasting network with WSJT-X, JTAlert, Log4OM, and Grid Tracker. This is getting deep!

  • @eddiegerlach7121
    @eddiegerlach7121 8 місяців тому +1

    Thank you for this tutorial. I am starting my new career in Cybersecurity and really appreciate the Malware-Traffic-Analysis suggestion. The class I'm taking just started discussing tools and I find Wireshark a bit overwhelming and intimidating, hence my search to your video. I believe this will assist greatly in gaining a greater understanding and competency with Wireshark! Subscribed!! :)

  • @SabrinaBlackburn-g5u
    @SabrinaBlackburn-g5u 3 місяці тому

    Subscribed half way through your video. I love the pacing you have in your content as well as the use and instructions. I encourage you to please continue posting things as I will certainly watch every one of them and apply them to my career.

  • @cr_cryptic
    @cr_cryptic 2 місяці тому +8

    Nice video, but- Ports 80 & 8080 are HTTP, Ports 443 & 8443 are HTTPS. :)

  • @furkanozdemir1ify
    @furkanozdemir1ify 6 місяців тому

    One single video explained all my questions about Wireshark. Thanks.

  • @JAXXYT-wt8tz
    @JAXXYT-wt8tz 8 місяців тому +1

    I am impressed by the easy way this boy giving the information you really make me eager to learn how this Wireshark works.

  • @manopublico9645
    @manopublico9645 3 дні тому

    That's an excellent tuto man. Kudos

  • @cals0ul
    @cals0ul 11 місяців тому +1

    I love this video and the resources you've provided. I have been studying and getting into cybersecurity and am grateful for your informational video. Subscribed!

    • @AnsonAlexander
      @AnsonAlexander  11 місяців тому

      That's awesome to hear, I'm glad to be able to help. Good luck with the degree and thanks for the sub!

  • @3DComputing
    @3DComputing 10 місяців тому +1

    Nice someone that actually makes it work in the real world for IOT and such, not just big url talk. Thanks

  • @isaacberhe5223
    @isaacberhe5223 Рік тому +1

    Do mor of Wireshark presentation you best teacher as I have seen it!

  • @morganwebster6636
    @morganwebster6636 Рік тому

    So helpful for a newbie like myself. Totally able to comprehend your whole video. Thank you.

  • @brucegavin7614
    @brucegavin7614 4 місяці тому

    Outstanding overview.
    Fed with a fire hose, but valuable.
    Kudos for an excellent presentation.

  • @soverintysons7548
    @soverintysons7548 2 місяці тому

    you killed this and saved me so many headaches. thank you

  • @Hatch-vg7pw
    @Hatch-vg7pw 10 місяців тому

    EASY TUTORIAL TO FOLLOW.
    Step by step clear explanation
    NOT CLICK BAIT!
    Thanks
    Subbed.

  • @mikewoodard1452
    @mikewoodard1452 10 місяців тому +2

    @AnsonAlexander I appreciate this. I was going to do this but I love your delivery and your examples appreciate your detail.

  • @DawgShawg
    @DawgShawg 4 місяці тому

    Thank you so much for this video. I'm trying to switch careers and have decided to focus on Cybersecurity. Currently taking the Google Cybersecurity Cert course. Hopefully everything goes well.

  • @kishorebabu432
    @kishorebabu432 Рік тому +1

    Excellent presentation

  • @bilongo3946
    @bilongo3946 2 місяці тому

    First time I see someone who simplify this tool for a beginner like me

  • @littop0
    @littop0 6 місяців тому +1

    great video, really helped me grasp the basics of wireshark

  • @MC-ew7sc
    @MC-ew7sc Рік тому +2

    Great update video.

  • @TylersLeftSock97
    @TylersLeftSock97 3 місяці тому

    This is fricken good bud! I just found your you tube page. I need wireshark for CCTV testing and troubleshooting.

  • @prernamullick3205
    @prernamullick3205 Рік тому +1

    Very Well Explained and Easy to understand

  • @inspectorratchet7614
    @inspectorratchet7614 Рік тому +1

    Thank you brother, you seem like a good man.

  • @DemMedHornene
    @DemMedHornene 28 днів тому

    Great video, was super useful!

  • @josephjefferson6368
    @josephjefferson6368 9 місяців тому

    Excellent, Anson. Deserves both thumbs up and "Subscribed." joe.

  • @EthicalKali
    @EthicalKali 3 місяці тому +1

    wow, u made me understand what i was struggling with thanks alot

    • @AnsonAlexander
      @AnsonAlexander  3 місяці тому

      You're welcome. I really tried to make this video in a way that would change peoples' understanding of Wireshark.

  • @Adventure_Food_Fun_US
    @Adventure_Food_Fun_US 6 місяців тому

    What a great video and explanation man! Good job!

  • @washingtonochieng5106
    @washingtonochieng5106 Рік тому +2

    Thank you

  • @christianminardi6230
    @christianminardi6230 11 місяців тому +1

    Thank you for the Knowledge!! Great videos

  • @daedalusjones4228
    @daedalusjones4228 5 місяців тому

    Excellent video. Content is great, your explanations are crystal clear, and made even clearer by the excellent production values (use of zoom, annotation, etc., making everything VISIBLE, easy to see and read).
    Great info! Thanks, brother!

  • @Kuruhabesha-s6m
    @Kuruhabesha-s6m День тому

    Great video 🙌

  • @ArjanSheraz
    @ArjanSheraz Рік тому +1

    Excellent presentation

  • @MosesGithinji-r4l
    @MosesGithinji-r4l 4 місяці тому +4

    To enable Packet Diagrams on Windows Wireshark version, go to Edit > Preferences > Appearance > Layout, and under Pane 3, choose Packet Diagram

  • @MrDayinthepark
    @MrDayinthepark 10 місяців тому +1

    Hi Anson, I'm routing UDP telemetry data from a drone to my external IP, then using router port forwarding to route to my PC, which I've assigned a fixed IP. It's not working, I downloaded Wireshark yesterday and tried to debug. I see a bunch of UDP transmissions, but my phone is connected so it might be just my phone. I was overwhelmed by all the data in Wireshark. Still trying to figure out where the problem is.

  • @rajeevpuri8319
    @rajeevpuri8319 Рік тому +1

    very good video .Thank You.

  • @mohammedimranchoudhari8082
    @mohammedimranchoudhari8082 5 місяців тому

    Loved your educational content and quality 😊.

  • @TureIMasterEquality
    @TureIMasterEquality 2 місяці тому

    Enjoyed the video and content, you got a new scriber 😅

  • @shreyaskarthik2185
    @shreyaskarthik2185 9 місяців тому

    really helpful , very consise and amazing pacing, thank you :)

  • @TheAffiliateKings
    @TheAffiliateKings 9 місяців тому

    Im In information tech doing my Bach, Wireshark is something i learning right now.

  • @theyogabios
    @theyogabios 2 місяці тому

    Great video Sir. Thank you.

  • @foxart1387
    @foxart1387 Рік тому +3

    Thanks!

  • @MarkinChiangMai
    @MarkinChiangMai 6 місяців тому

    Excellent video. Thank you, brother.

  • @jayhmedmustafa
    @jayhmedmustafa 6 місяців тому

    nice job my friend, greats from Morocco

  • @danielkolesnikov1278
    @danielkolesnikov1278 5 місяців тому

    from what Im seeing on the internet port 80 is used for regular http communication but port 443 is used for secure https communication

  • @ao4514
    @ao4514 11 місяців тому +1

    Hey Alex, would you consider doing some contents on how to detect malware or spywares utilizing Wireshark?!

    • @AnsonAlexander
      @AnsonAlexander  11 місяців тому

      It's definitely on my radar. It's just that setting up the environment is tough. I think I would use the PCAPS from Malwarebytes. Thanks for the suggestion, I will take it into account for sure!

  • @MrKashifiq
    @MrKashifiq 8 місяців тому

    Outstanding and thanks for sharing the knowledge!!

  • @andrewwhite889
    @andrewwhite889 10 місяців тому

    Excellent tutorial. Thank you.

  • @francissaanane5874
    @francissaanane5874 9 місяців тому

    Thank You, awesome Wireshark details.

  • @train4905
    @train4905 Рік тому

    Awsome😊😊

  • @ayessedd
    @ayessedd Рік тому +1

    hey, what to do after you want to finish monitoring the network? after checking the network with wireshark, many sites refuse to give me access to browse, which didn't happen before

  • @m.haseebshahzad9058
    @m.haseebshahzad9058 7 місяців тому

    best one very concise and save alot of time

  • @user-mc4lb1jy7b
    @user-mc4lb1jy7b Рік тому

    Thanks for sharing.
    Quick question, can you use Wireshark to only monitor activities on your personal computer or laptop?

  • @TheGalactusDiet
    @TheGalactusDiet 2 місяці тому

    more of this please

  • @konteezy203
    @konteezy203 11 місяців тому +1

    This is a great video

    • @AnsonAlexander
      @AnsonAlexander  11 місяців тому

      Thanks - sorry again about the port mix up.

  • @mohdkaifkhan2012
    @mohdkaifkhan2012 3 місяці тому

    Great Video👍

  • @allangomez9890
    @allangomez9890 Рік тому

    Thanks for the great explanation.

  • @Rich-can-do
    @Rich-can-do 23 дні тому

    I am trying to use wireshark to fault find my a game I play. It might not give me the full picture, but maybe it can give me a direction to look at.

  • @K.K.BuddhikaChathuranga
    @K.K.BuddhikaChathuranga Місяць тому

    Thank you

  • @WesleyKanye
    @WesleyKanye 11 місяців тому +1

    Thank you sir!

  • @terrykilpatrick5799
    @terrykilpatrick5799 Рік тому +3

    Port 80 is unencrypted traffic via http and 443 is encrypted traffic via https, I think you mistakenly said port 80 for secure traffic.

    • @Fantasmagorikus
      @Fantasmagorikus Рік тому

      Yup I found this out while looking through the video as well.
      The statement "generally to see secure traffic you need to look on port 80" is incorrect under conventional networking standards. Here's a clarification:
      - **Port 80** is traditionally used for **HTTP** traffic, which is **not secure**. HTTP (Hypertext Transfer Protocol) is the foundation of data communication on the World Wide Web, and when it's used without SSL/TLS, the data is sent in plaintext. This can be easily intercepted and read by third parties.
      - **Port 443** is used for **HTTPS** traffic, which is **secure**. HTTPS (HTTP Secure) encrypts the data sent and received with SSL (Secure Sockets Layer) or TLS (Transport Layer Security) protocols, providing confidentiality, integrity, and authentication. This is why when you access a website with HTTPS, your browser shows a lock icon, indicating that the connection is secure.
      To see secure traffic using a network protocol analyzer like Wireshark, you would typically filter for traffic on port 443, not port 80. Filtering traffic on port 443 allows you to see encrypted HTTPS communication. However, without the appropriate decryption keys, you would not be able to see the plaintext of the encrypted traffic; you would only see that the data is being encrypted and transferred securely.
      There might be some confusion or a misunderstanding in the way the statement was made. If the intent was to demonstrate or inspect HTTPS traffic specifically, then the correct port to focus on would be 443, not 80. It's possible that the context in which this statement was made was misunderstood, or there was a communication error in the tutorial. Always remember, for secure web traffic, look towards port 443 for HTTPS.

  • @aheimdahl5201
    @aheimdahl5201 27 днів тому

    Will Wireshark show an Outbound connection that has been stopped by, say Malwarebytes?
    I need to find out about a blocked Outbound connection - to find out what app or file it is using.

  • @albfresh
    @albfresh 8 місяців тому

    Extremely helpful thanks

  • @dragospalade9460
    @dragospalade9460 8 місяців тому

    Really useful. Thanks!

  • @cherronetwork8729
    @cherronetwork8729 Рік тому

    thanks for well explaining

  • @alfonstabz9741
    @alfonstabz9741 4 місяці тому +1

    thanks man

  • @andeo1707
    @andeo1707 5 місяців тому

    Can you use Wireshark to see which cables inside a keystone are potentially faulty?

  • @macm3086
    @macm3086 4 місяці тому +1

    Thanks !!!

  • @SandeepKumar-bv6wl
    @SandeepKumar-bv6wl 4 місяці тому +1

    Sir on switch ...switch does not allow to capture other devices one to one conversations ,it only allows traffic between your pc and pc devjces broadcast mcast ARP stp traffic only ...not other pc to pc communications

    • @Graham_Wideman
      @Graham_Wideman 3 місяці тому

      You can get an inexpensive "managed" switch (eg: TP-Link TL-105E) which can be configured for various special functions. One function is "Port Mirroring", which configures a port to duplicate the traffic on another port. So you can interpose this switch in a leg of the existing network, and you can attach your PC/Mac to the mirror port. You can then use WireShark to "snoop" on the ongoing traffic on the original network.

  • @QueenChineye-di8ie
    @QueenChineye-di8ie 5 місяців тому

    Very simplified and detailed.. Do you have tutorials on using splunk

  • @MUHAMADBINTAYYIB
    @MUHAMADBINTAYYIB 10 місяців тому

    gudluck for yours new project

  • @TOMESHTI
    @TOMESHTI Рік тому

    Thanks bruh!
    Nice vid.

  • @bonnefe9943
    @bonnefe9943 11 місяців тому +1

    Good explanation about wireshark but is wireshark safe to use?

    • @AnsonAlexander
      @AnsonAlexander  11 місяців тому

      Thanks and good question. Wireshark doesn't introduce any security concerns that aren't already there. An insecure network is an insecure network regardless of whether or not you're using Wireshark. If anything, you could use it to do a manual security scan on an insecure network. If you bring in network security guys to do almost anything, Wireshark is one of the first software applications they're going to open up.

  • @Pvail26
    @Pvail26 6 місяців тому

    Do you have more videos on Wireshark?

  • @johnvardy9559
    @johnvardy9559 11 місяців тому

    Hi anson great video.on malware analysis there arent anymore the answers.

  • @phillipmaser132
    @phillipmaser132 8 місяців тому

    I have a Programmable Logic Control that sends out packets but wireshark cant see the data as it sends to the pc. Filtering use TCP.port == 1234 no data on this port coming for the PLC. have if i use labview and build out a TCP send protocol it see it and the data I am sending out. I can filter IP or Port works fine?

  • @roseandmose
    @roseandmose Рік тому

    You are very helpful thank you

  • @aslammadathil7871
    @aslammadathil7871 Рік тому +1

    superb

  • @cosmicblack
    @cosmicblack 5 місяців тому

    is it possible to capture the request made by Internet Download Manager with wireshark? i cant find out how

  • @rayalvarez5172
    @rayalvarez5172 Рік тому

    excellent intro

  • @Darkregen9545
    @Darkregen9545 11 місяців тому

    Captured an IP private IP that wasn't listed in clients for my router utilizing my wifi and i was trying to figure out why this IP was receiving massive amounts of packets. I then tried blocking all tcp and udp packets and for some reason one of the computers in my house that had a different private ip no longer had internet connection. Why would a device have two private IPs?

  • @bayoumick1826
    @bayoumick1826 4 місяці тому

    I'm having a very hard time finding HTTP protocols, and when I expand on the HTTP stream, the website where I am at does not show up. I have turned on all the dissectors and nothing, it usually takes a long while for me to get a HTTP protocol packet, but it does not show the actual website I am visiting.

    • @JJFlores197
      @JJFlores197 3 місяці тому

      Most modern webpages use HTTPS rather than HTTP. HTTPS is an encrypted version of HTTP which offers more security and privacy compared to HTTP which is just plaintext. That's why you're not seeing much HTTP traffic.

  • @Starlite4321
    @Starlite4321 9 місяців тому

    Do I understand correctly that Wireshark doesn't have the capability to inspect COM ports, for example on a Win10 machine ?

    • @angeloc700
      @angeloc700 8 місяців тому

      Can't you just use PuTTY for that?

  • @noobtube5555
    @noobtube5555 42 хвилини тому

    good shit

  • @janrymar2229
    @janrymar2229 Рік тому

    Hello, can you show or tell me how and where to install the master key on mac, where the protocols are stored, it's clear on windows, but for mac I can't find the answer, please help

  • @franksterkb891
    @franksterkb891 Рік тому

    Thank you!!!

  • @1DumbSquirrel
    @1DumbSquirrel 2 місяці тому

    so can't you do this stuff 12:20 just by right clicking a inspecting

    • @JJFlores197
      @JJFlores197 2 місяці тому

      If you're talking about inspecting within a web browser, yes you can do that. however, when you're working in Wireshark, you can't inspect encrypted traffic, unless as he says, you have the decryption key.

  • @BigBoy-nw2ur
    @BigBoy-nw2ur 11 місяців тому +1

    I'm a complete noob at this. Just installed it and have no idea what to do..hopefully your video helps

    • @AnsonAlexander
      @AnsonAlexander  11 місяців тому

      It definitely should - one of my main goals was showing people what to look for. Good luck!