Packet captures courtesy of the Wireshark Wiki

If you've ever needed to get intimately familiar with a protocol, picking it apart with a packet analyzer is the way to do it. Unfortunately, we often don't have direct or immediate access to the traffic flow we wish to observe. Fortunately there are a number of sources around the web which provide various packet captures pre-assembled and free for download.

One of my favorite such sources is the Sample Captures page of the Wireshark Wiki.

wireshark_wiki_captures.jpg

While there is certainly a wealth of captures, the page is admittedly a bit chaotic (wikis aren't the ideal catalyst for file management). Rather than relying on the hastily arranged categories, I recommend doing a full-page text search for items of interest. Sharing is encouraged, and particular requests can be read/fulfilled toward the bottom of the page.

A word of warning: keep in mind that anyone can contribute captures. Given the history of vulnerabilities in some of Wireshark's protocol descriptors, proceed with caution and never open untrusted captures with elevated privileges.

About the Author

Jeremy Stretch is a networking engineer and the maintainer of PacketLife.net. He currently lives in the Raleigh-Durham area of North Carolina. Although employed full-time out of necessity, his true passion lies in improving the field of network engineering around the world. You can contact him by email or follow him on Twitter.

Comments

cool

Its ironic, I just taught a group of CCNA students about wireshark yesterday. I think tomorrow I'll share this post with them and let them check out the wireshark wiki. Nicely done!...as usual.

Very nice find. I'm having fun looking at caps of apps I don't run and seeing what the traffic looks like. :)

Leave a Comment


Register to comment as a member. You'll look cooler.

Optional; will not be displayed publicly or given out.

No commercial links. Only personal (e.g. blog, Twitter, or LinkedIn) and/or on-topic links, please.
What is the decimal equivalent of 0x5F0E?