This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi, I've been trying to capture Telegram messaging application's packets (for my class project) but I couldn't get anything out of the punch of captured packets I got.

Telegram does AES-256 encryption over the users' messages and then send it using normal-Not SSL-transportation protocols (e.g. TCP,HTTP,UDP, etc..)

I tried these capturing scenario:

  • Connecting both mobile phones (sender & receiver) to the same access point that my Laptop-where wireshark is running-connected to.
  • making my laptop as an access point where the two phones are connected to (that's to make sure the packets go through the NIC card in case the router is not allowing packet to be broadcasted)

So in my capture filter I tried many filters I assume the most relevant are :

  • HTTP only: I got many packets, which is useless to check every single one of the 269386 packets captured. that is in the case of scenario one of the capturing trials. So I modified the filter and come up with the second filter.
  • HTTP with my mobile phone IP address (i.e http && ip.addr) but I got no packets at all. though my phone is the sender (in both capturing scenarios).

Any ideas what's wrong or what I'm missing here

P.S wireshark is set in promiscuous mode

asked 20 Dec '14, 07:41

captin's gravatar image

captin
11224
accept rate: 0%


Any ideas what's wrong or what I'm missing here

MTProto supports TCP/UDP and HTTP. If you did not ensure that the client was using HTTP, you won't see anything with the filter http !!

You should better filter for the client IP address and the destionation port, based on the client protocol.

ip.addr eq x.x.x.x and tcp.port eq yyyy

Regards
Kurt

permanent link

answered 27 Dec '14, 08:53

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×752
×549
×349
×76
×43

question asked: 20 Dec '14, 07:41

question was seen: 4,348 times

last updated: 27 Dec '14, 08:53

p​o​w​e​r​e​d by O​S​Q​A