Apocrypha

wireshark

Network protocol analyzer (sniffer)

Wireshark is the world's foremost network protocol analyzer, and is the de facto (and often de jure) standard across many industries and educational institutions. Wireshark has a rich feature set which includes 1) deep inspection of hundreds of protocols, with more being added all the time, 2) live capture and offline analysis, 3) standard three-pane packet browser, 4) captured network data can be browsed via a GUI, or via the TTY-mode TShark utility, 5) the most powerful display filters in the industry, 6) rich VoIP analysis, 7) read/write many different capture file formats: tcpdump (libpcap), Catapult DCT2000, Cisco Secure IDS iplog, Microsoft Network Monitor, Network General Sniffer® (compressed and uncompressed), Sniffer® Pro, and NetXray®, Network Instruments Observer, Novell LANalyzer, RADCOM WAN/LAN Analyzer, Shomiti/Finisar Surveyor, Tektronix K12xx, Visual Networks Visual UpTime, WildPackets EtherPeek/TokenPeek/AiroPeek, and many others, 8) capture files compressed with gzip can be decompressed on the fly, 9) live data can be read from Ethernet, IEEE 802.11, PPP/HDLC, ATM, Bluetooth, USB, Token Ring, Frame Relay, FDDI, and others, 10) decryption support for many protocols, including IPsec, ISAKMP, Kerberos, SNMPv3, SSL/TLS, WEP, and WPA/WPA2, 11) coloring rules can be applied to the packet list for quick, intuitive analysis, 12) output can be exported to XML, PostScript®, CSV, or plain text.

⚠ Security advisories affect this package: GLSA 202402-09, GLSA 202309-02

Available in

OverlayNewestEbuildsLast activity
gentoo gitweb ↗ 4.6.7 3 14 h details ›

Versions & arches

VersionOverlay amd64arm64x86ppc64riscvarmhppaloong Committed
9999 LIVE gentoo follows upstream — no keywords view · download · history ↗
4.6.7 gentoo amd64 stable arm64 stable x86 stable ppc64 stable riscv testing arm stable hppa testing loong testing view · download · history ↗
4.6.6 gentoo amd64 stable arm64 stable x86 stable ppc64 stable riscv testing arm stable hppa testing loong testing view · download · history ↗

Use flags of 4.6.7

  • androiddump Install androiddump, an extcap interface to capture from Android devices
  • bcg729 Use media-libs/bcg729 for G.729 codec support in RTP Player
  • brotli Enable Brotli compression support
  • +capinfos Install capinfos, to print information about capture files
  • +captype Install captype, to print the file types of capture files
  • ciscodump Install ciscodump, extcap interface to capture from a remote Cisco router
  • +dftest Install dftest, to display filter byte-code, for debugging dfilter routines
  • doc Add extra documentation (API, Javadoc, etc). It is recommended to enable per package instead of globally
  • dpauxmon Install dpauxmon, an external capture interface (extcap) that captures DisplayPort AUX channel data from linux kernel drivers
  • +dumpcap Install dumpcap, to dump network traffic from inside wireshark
  • +editcap Install editcap, to edit and/or translate the format of capture files
  • +gui Enable support for a graphical user interface
  • http2 Enable support for the HTTP/2 protocol
  • http3 Install net-libs/nghttp3 for enhanced HTTP3 analysis
  • ilbc Build with iLBC support in RTP Player using media-libs/libilbc
  • kerberos Add kerberos support
  • lua Enable Lua scripting support
  • lz4 Enable support for lz4 compression (as implemented in app-arch/lz4)
  • maxminddb Use dev-libs/libmaxminddb for IP address geolocation
  • +mergecap Install mergecap, to merge two or more capture files into one
  • +minizip Build with zip file compression support
  • +netlink Use dev-libs/libnl
  • opus Enable Opus audio codec support
  • pkcs11 Add support for PKCS in net-libs/gnutls
  • +plugins Install plugins
  • +pcap Use net-libs/libpcap for network packet capturing (build dumpcap, rawshark)
  • +randpkt Install randpkt, a utility for creating pcap trace files full of random packets
  • +randpktdump Install randpktdump, an extcap interface to provide access to the random packet generator (randpkt)
  • +reordercap Install reordercap, to reorder input file by timestamp into output file
  • sbc Use media-libs/sbc for playing back SBC encoded packets
  • selinux !!internal use only!! Security Enhanced Linux support, this must be set by the selinux profile or breakage will occur
  • +sharkd Install sharkd, the daemon variant of wireshark
  • smi Use net-libs/libsmi to resolve numeric OIDs into human readable format
  • snappy Enable support for Snappy compression (as implemented in app-arch/snappy)
  • spandsp Use media-libs/spandsp for for G.722 and G.726 codec support in the RTP Player
  • sshdump Install sshdump, an extcap interface to capture from a remote host through SSH
  • ssl Add support for SSL/TLS connections (Secure Socket Layer / Transport Layer Security)
  • sdjournal Install sdjournal, an extcap that captures systemd journal entries
  • test Enable dependencies and/or preparations necessary to run tests (usually controlled by FEATURES=test but can be toggled independently)
  • +text2pcap Install text2pcap, to generate a capture file from an ASCII hexdump of packets
  • +tshark Install tshark, to dump and analyzer network traffic from the command line
  • +udpdump Install udpdump, to get packets exported from a source (like a network device or a GSMTAP producer) that are dumped to a pcap file
  • wifi Install wifidump, to dump and analyse 802.11 traffic
  • xxhash Enable dev-libs/xxhash support for hashing
  • zlib Add support for zlib compression
  • +zstd Enable support for ZSTD compression
  • +filecaps Use Linux file capabilities to control privilege rather than set*id (this is orthogonal to USE=caps which uses capabilities at runtime e.g. libcap)
  • verify-sig Verify upstream signatures on distfiles
2 expansion flags (python targets, ABIs, cpu flags…)
  • lua_single_target_lua5-3
  • lua_single_target_lua5-4

Runtime dependencies of 4.6.7

show 102 lines