« Using beamer with lucimatxEVT/WOTE 2009 Update »

33 comments

  1. § Keith said on :
    Perfect! Just what I needed to get Wireshark configured. Thanks!
  2. § joe® Email said on :
    great!
  3. § Dum Email said on :
    Thanks, very straight forward !!
  4. § Greg Email said on :
    Worked like a charm. Although I still need to start wireshark via the Terminal window by:

    In terminal:
    cd /Applications/Wireshark.app/Contents/MacOS/
    then command
    sudo ./wireshark

    I must have done something wrong in the ChmodBPF file.
  5. § joe® Email said on :
    Yeah, you need to revisit the `chown foobar:admin /dev/bpf*` line and replace foobar with the name of the user you want to run it as (type `whoami` at the terminal to get that username).
  6. § Greg Email said on :
    Works like a charm!!!

    You have saved me from countless hours of frustration.

    Thanks
  7. § Eric said on :
    Great ! Thank you !
  8. § Chris Email said on :
    Thank you! Saved me a ton of time
  9. § Jason said on :
    Thanks!
  10. § Garth Email said on :
    Hey thanks for the advice.... like others, the setup was now a breeze. After an hour or so, previously, of frustration, I suppose I could've googled this earlier to save myself the time. Anyway, thanks for the help.
  11. § hal Email said on :
    Works really well. Additional problem I had was that my X11 wasn't working properly. I had to download a new version of XQuartz(x11): http://xquartz.macosforge.org/trac/wiki

    The explanation is at:
    http://lists.apple.com/archives/X11-users/2008/Aug/msg00164.html

    Hal
  12. § loi Email said on :
    Hi,

    i tried this, and i think it is a much better guide than the one they provide in the Wireshark.dmg package but having said that i still cannot see the right interfaces. all i have is:

    - en0: IP unknown
    - fw0: IP unknown
    - en1: does have an IP but it looks something like a mac address, for example: fe34::cd0:a1f5:123ce:aef0 and is the only interface capturing packets right now...
    - lo0: also has an IP but looks something like: fed0::1

    those are the only interfaces available to me... i don't know how to capture packets from the wireless network since i cannot find the interface for it. i followed all your instructions there but maybe i am still missing something...

    also my X11 version is:
    - XQuartz 2.1.6 (xorg-server 1.4.2-apple33)

    i don't know if the problem is there but someone mentioned in the comments that they had to update theirs. well any help would be greatly appreciated.

    just so you know what i'm trying to do... originally i wanted to capture the packets sent from my iPod touch via the wireless network. that is why i wanted to see if wireshark can capture these informations using a wireless interface.

    thanks.
  13. § joe® Email said on :
    Alas, I'm not sure how to help you... do let me know if you figure it out!
  14. § Bob Guru said on :
    I love you. Why is this not in their ReadMe?
  15. § joe® Email said on :
    ::)
  16. § irrationalidiot Email said on :
    Worked beautifully. Thanks!
  17. § iJim Email said on :
    Hi, i use tiger and i can't run wireshark, i think i wrong some step! Someone could help me?
    Excuse me for the bad language i'm italian
  18. § jayray Email said on :
    Thanks Joe!
  19. § Mars Email said on :
    My /Library/StartupItems/ChmodBPF will not run. I have it in the folder, I am an admin, THE admin, I run as the admin, and it says insecure item at startup and does NOT offer a "fix" button at all. Even though the Mac help mentions the fix button. No fix button.

    I have even selected every file of the command line folder, get info and set to read/write for everything, but hand. The startup ChmodBPF fails, and I get a boatload of errors when running wireshark.
  20. § Vi Email said on :
    Thank you for this detailed procedure. Definitely couldn't have done it without your help. One last note, I did run into a security error with chmodbfd.

    "Insecure Startup Item disabled.
    /library/StartupItems/ChmodBPF" has not been started because it does not have the proper security setting."

    Maybe I missed a step...

    Anyway, a quick search on the Internet showed a solution from Nick Kleinschmidt's Blog.
    http://kleinsch.com/2009/10/03/wireshark-chmodbpf-errors-on-snow-leopard/comment-page-1/#comment-29

    Thanks again.
  21. § joe® Email said on :
    Yeah, it looks like if you're doing a fresh install on Snow Leopard, the permissions aren't set correctly on ChmodBPF/. I'll add a note, thanks!
  22. § Chris Gregg Email said on :
    One more quick fix for a possible non-start issue on Snow Leopard: on my system there was a problem with the ~/.fontconfig font caches. Removing this folder allowed Wireshark to run (it crashed on startup initially).
  23. § Nikhil Email said on :
    Awesome. It worked just out of the box. Thanks
  24. § EK Email said on :
    Its easier to login as 'root', unhide all folders,then you can drag and drop everything you need to copy or move...no confusing terminal commands. Rehide folders when done, then reboot. Done.
  25. § joe® Email said on :
    I'd recommend sticking with the terminal commands, folks...
  26. § spockr said on :
    And don't forget to add the number you first thought of. Really, how ridiculous it is that you have to jump through these hoops.
  27. § Pradeep Email said on :
    thanks!
  28. § Dan Email said on :
    One more hint: I just installed the latest version normally (drop in aps) and then couldn't access the interfaces (as expected). If I ran as root (sudo Wireshark as suggested above) I could see the interfaces, but didn't appear to be able to access the Wireshark window thru the GUI. It turns out that there's a pop-up warning window saying "Hey, you're running as root and you could ruin everything so be careful", but the window pops-under, so I didn't find it until much later. Just acknowledge that you know what you're doing (even if you don't) and it seems to work find. This is on OS 10.5 with Wireshark Version 1.2.5 (SVN Rev 31296)
  29. § andrew Email said on :
    I did all the steps above and for some reason i do not have a /dev/bpf* file or folder. what do i do?
  30. § joe® Email said on :
    sorry, I have no clue... let me know if you figure it out.
  31. § Ray Email said on :
    I'm a little concerned about changing the ownership of the interface device files to a general user. Why not add my user name to the wheel group? Thx
  32. § Tim Fetter Email said on :
    Thank you so much for sharing your knowledge. I was installing on the snow cat and was getting the permissions error from the startup items. I took your advice and am now happily? looking at mountains of data. I have no idea what I was doing in Terminal, but it worked.
  33. § CSK Email said on :
    love u dude :)

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)
Contact. (cc) 2010 by Joseph Hall. blogsoft / webhosts / blog ads.
Design & icons by N.Design Studio. Skin by Tender Feelings / Evo Factory.