Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Anyone decoding SSL with Sniffer or Wireshark??

Status
Not open for further replies.

dane775

Technical User
Oct 28, 2004
151
CA
All,

I'm interested in peoples experiences with respect to SSL decode using Sniffer products or Wireshark (or anything else you might be using).

We have Infinistream Sniffer's where I work. Decoding SSL is done through the use of *unsupported* software they offer on their web site called "Tools". I've never been able to get that to work properly.

Using Wireshark requires that you store an unencrypted copy of the RSA key on your PC and point to it. I've had some success with that. Decoding my own transactions shows some frames being decoded, while others remain encrypted??

In addition, it looks like Wireshark broke (or maybe they decided it was better this way??) part of their decode in the List/Info section after version 0.99.5. In that version, decoded SSL was listed as HTTP in the top pane (List area)...and the GETs, POSTs, etc. were clearly shown in that area. If you're looking for a 503 error or a specific GET, it was easy to scroll through looking for it. In recent versions you have to highlight the frame and select the "decrypted SSL data" tab to see it....or...you have to select the appropriate frame and use the "follow SSL stream" feature.

I'm just beginning to learn a bit more about SSL, but from what I can see so far...it can be a pain to troubleshoot.

I'm interested in knowing if anyone else has had success and what they were using. Thanks in advance for any comments - Dane
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top