Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

webshark

Wireshark in the browser. A static page and a small Go server over sharkd, which does all the dissecting — point it at a directory of captures and read them from a browser, with no client to install.

  • Packet list — paged and virtualised, so a 600 MB capture opens as fast as a small one; Wireshark's own columns and coloring rules.
  • Flow view — Wireshark's flow graph: a lane per address, an arrow per frame, lanes draggable into the order you want to read them in.
  • Dissection tree and bytes — the full protocol tree, hex with the selected field highlighted, one tab per data source.
  • Display filters — compiled by sharkd as you type, with field-name completion.
  • Captures list — sizes, capture times and a protocol summary per file; upload by drag-and-drop, download, close.
  • IMS extras — a Lua plugin relating SIP to Diameter by subscriber identity, and ESP SAs recovered from a capture's own AKA registration so protected Gm traffic dissects (see src/esp.go).

Run

docker run --rm -p 8085:8085 -v /path/to/captures:/captures \
    ghcr.io/lyatanski/webshark

Then open http://localhost:8085. Captures are whatever files are in the mounted directory — nothing is copied and nothing is written except uploads.

Configuration is environment variables, all with the defaults shown:

CAPTURES=/captures directory served
LISTEN=:8085 listen address
SHARKD_SESSIONS=4 captures kept loaded at once
SHARKD_IDLE=600 seconds before an idle capture is unloaded
SCAN_FRAMES=20000 frames dissected for the protocol summary
WEB= serve the UI off disk instead of the embedded copy

Build

docker build . builds sharkd from Wireshark master with Lua enabled and the server around it; --build-arg WIRESHARK=v4.6.7 pins a release instead. CI rebuilds and pushes the image on every push.

Layout

src/main.go      HTTP handlers and the JSON API (documented at the top of the file)
src/sharkd.go    one sharkd per open capture, and the pool that ends them
src/capture.go   capture times from the file header, cached protocol scans
src/esp.go       ESP SAs from a capture's SIP registration; also `webshark -esp <file>`
src/web/         the UI - no framework, no build step: app.js is what the browser runs
plugins/ims.lua  SIP ↔ Diameter correlation
preferences      hidden port columns the flow view labels arrows with, plus ESP settings
colorfilters     coloring rules

Working on the UI

Mount the working tree over the embedded copy — no rebuild needed for JS/CSS/HTML:

docker run --rm -p 8085:8085 -v /path/to/captures:/captures \
    -e WEB=/web -v "$PWD/src/web:/web:ro" ghcr.io/lyatanski/webshark

About

web based wireshark

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Packages

Contributors

Languages