How do I get HTTP in Wireshark?
We have been studying Wireshark and we think that it will be a useful tool.
But as we go to the more complex sites, HTTP becomes a challenge.
How do I get into HTTP in Wireshark so that I can capture the data? Thanks in advance. Randy. I believe you are looking for the HTTPMUX sub-protocol in Wireshark. This is a generic protocol used for handling multiple HTTP flows within a single thread. It is part of the general HTTP dissector included in the wireshark package and not meant to represent any particular transport or protocol. Wireshark automatically detects this type of information when present and captures traffic as usual, using one capture (TCP) per http flows.
See: for more info and the official Wireshark wiki on this matter.
What is the HTTP view in Wireshark?
Wireshark is a network protocol analyzer that is great for a variety of reasons, but what exactly is the HTTP view in Wireshark?
The question is difficult to answer in an objective way, because there are many different meanings. In the broadest sense, the HTTP view shows you all of the HTTP requests that your system makes over a period of time. But in the narrowest sense, the HTTP view shows you the HTTP requests that are relevant to your application, and ignores others. This article will help you understand how to interpret the HTTP view in Wireshark, and provide some examples that will help you get started.
The problem with the HTTP view in Wireshark. Before I explain how to interpret the HTTP view, it's important to understand why it is so difficult to interpret in the first place. First, the term HTTP view is ambiguous. The HTTP view is a special pane in Wireshark, which has been around for a while and is often recommended for basic analysis of HTTP traffic. You may have seen this window before and wondered, Why doesn't my program open the HTTP view when I run Wireshark? and Why doesn't Wireshark automatically show me the HTTP view when I open a new packet?
The reason the HTTP view is difficult to interpret is that it doesn't really show you the HTTP requests that are relevant to your application. In other words, the HTTP view does not show you any HTTP requests that your program actually makes.
To understand why the HTTP view is difficult to interpret, think about how you would like to see your HTTP requests in Wireshark. If you are a web developer, you probably want to see every request that your website sends to your web server. Maybe you want to see all of the image requests your website makes, or all of the JavaScript requests that your website makes. This is certainly useful information, but it's also highly impractical. Imagine if you had to manually view all of the images on your website to determine which ones were actually used by your users, and then you would have to determine which images are important enough to be worth your time and attention.
In reality, you probably don't care about all of these requests that your website makes.
Why is there no HTTP in Wireshark?
I'm sure that we are all familiar with the fact that there is a TCP stream that accompanies HTTP traffic.
Why, then, is there no HTTP in Wireshark? You know, like we have a stream for TCP and a stream for UDP, why not an HTTP stream for HTTP? I have seen some mention of the HTTP stream being defined as part of a draft spec that Wireshark implements, but not any explanation or indication as to why there isn't an HTTP stream. Anybody know what's up with that? For example, if you're using the wireshark/firefox plugin: right click on a packet, select "Edit HTTP Stream Info". If you're sniffing on a port other than 80, you can even right-click on a packet and select "Edit HTTP Stream Info" on a port other than 80, and change the port in the drop-down box, to enable this.
The reason is that HTTP is used primarily over TCP, so there really isn't a concept of the wire protocol per se. It's just used as a transport layer protocol. So why would you want to treat it as a standalone protocol? That's like treating FTP as a protocol in and of itself, when it's only really a protocol on top of TCP.
That's what I was thinking. I guess one could make a similar argument about DNS, DNS is more protocol than an over the wire protocol.
This is very true, and I've always wondered about it as well. I'm thinking that even looking at packets is better than using HTTP headers and assuming they'll just work with Wireshark. Then again, if you have never been able to use Wireshark without seeing an HTTP header, then my point doesn't hold much water.
If you think about it, its not like the "HTTP protocol" has any sort of formal definition. There are different interpretations of what it is, whether it's only about the HTTP data in the TCP stream (which is what it should be) or if it includes ALL the TCP data on a certain port, or just the HTTP data.
Related Answers
How to analyse Wireshark traffic?
What is the difference between Protocol and Application? How do I f...
Is there a Wireshark for Mac?
(I'm on OS X 10.6.8) After using it for a while, now my question is no...
How to capture Wi-Fi on Wireshark?
In this article, I'll teach you how to capture the Wi-Fi traffic on Wire...