Fri, 05 Sep 2008

Running Wireshark as a non-root user

As pointed out on the Wireshark Wiki, in order to capture data, Wireshark needs root privileges. Running Wireshark as root isn't particularly safe. Wireshark even warns you when you do that. A safer method involves capturing data using dumpcap (included with Wireshark) as root, then later looking at the saved captured data using Wireshark as a non-root user. In this way, at least those parts of Wireshark which parse the data don't run with root privileges. I wonder whether there really isn't any more comfortable method - one which allows you to look at the data in real time without being root - but maybe there just isn't.

Posted on 05 Sep 2008 at 17:30 in /technology/internet. -- Permalink

