This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Penetration Testing

0

Can Wireshark be used for internal penetration testing? I am new to penetration testing but I need to learn quickly and start performing internal scans and tests.

asked 24 Mar '15, 08:02

japonzio's gravatar image

japonzio
6111
accept rate: 0%


2 Answers:

0

Yes and no. Wireshark is a recording/analyzing tool, it does not scan or otherwise create packets. Still, Wireshark is helpful in recording your scans (e.g. performed by using nmap) to be able to see/prove afterwards what the scan really did.

answered 24 Mar '15, 09:28

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Thanks for the feedback. I will have to get familiar with Wireshark and learn how to use it. I am not sure if I need to keep looking for a good pen test program or just use Wireshark.

(25 Mar '15, 07:35) japonzio

0

I am not sure if I need to keep looking for a good pen test program or just use Wireshark.

The most important thing for pentesting is not a single tool/program, it's good old Know-how. Knowing protocols, network architectures, web architectures, typical security problems/bugs, cryptography know how, and many more things.

Having said that, there is not one single best pentest tool. There a lot of "supporting" tools you can use during the pentest process. One good collection of such tools is Kali Linux, which also includes Wireshark.

http://www.kali.org

Regards
Kurt

answered 25 Mar '15, 17:50

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 25 Mar '15, 17:50