{"id":21,"date":"2014-08-14T11:31:01","date_gmt":"2014-08-14T09:31:01","guid":{"rendered":"http:\/\/wp.famlarsson.net\/?p=21"},"modified":"2014-08-15T10:29:06","modified_gmt":"2014-08-15T08:29:06","slug":"usb-capturing","status":"publish","type":"post","link":"https:\/\/wp.famlarsson.net\/?p=21","title":{"rendered":"USB-capturing"},"content":{"rendered":"<h3 class=\"post-title entry-title\">Capturing USB data through Wireshark<\/h3>\n<div class=\"post-header\"><\/div>\n<div dir=\"ltr\" style=\"text-align: left;\">1)Install Wireshark through Update Manager.2)Enable usbmon through below commands<\/p>\n<pre>#mount -t debugfs none_debugs \/sys\/kernel\/debug<\/pre>\n<pre>\u00a0#modprobe usbmon<\/pre>\n<pre>\u00a0#ls \/sys\/kernel\/debug\/usb\/usbmon<\/pre>\n<pre>0s  0u  1s  1t  1u  2s  2t  2u  3s  3t  3u  4s  4t  4u<\/pre>\n<p>3)Check the USB devices through tshark<br \/>\n#sudo tshark -D<\/p>\n<p>E.g:<br \/>\n#sudo tshark -D<br \/>\ntshark: Lua: Error during loading:<br \/>\n[string &#8221;\/usr\/share\/wireshark\/init.lua&#8221;]:45: dofile has been disabled<br \/>\n1. eth0<br \/>\n2. wlan0<br \/>\n3. usbmon1 (USB bus number 1)<br \/>\n4. usbmon2 (USB bus number 2)<br \/>\n5. usbmon3 (USB bus number 3)<br \/>\n6. usbmon4 (USB bus number 4)<br \/>\n7. any (Pseudo-device that captures on all interfaces)<br \/>\n8. lo<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>4)List of de-vices connected can be seen through the command<br \/>\n#usb-devices<\/p>\n<p>or<\/p>\n<p>#lsusb which I prefere.<\/p>\n<p>5) To have wireshark or tshark gain access to usbmon type<\/p>\n<p>#sudo chgrp wireshark \/dev\/usbmon*<\/p>\n<p>and<\/p>\n<p>#sudo chmod 754 \/dev\/usbmon*<\/p>\n<p>6) Now you can use wireshark or tshark without root access<\/p>\n<p>7)<br \/>\nIf the device is connected to usb2,then to capture through wireshark command has below:<\/p>\n<p>#tshark -i usbmon2 -w 1.pcap<\/p>\n<p>Open the capture file through Wireshark GUI.<\/p>\n<p>or<\/p>\n<p>Capture direct from wireshark GUI.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Capturing USB data through Wireshark 1)Install Wireshark through Update Manager.2)Enable usbmon through below commands #mount -t debugfs none_debugs \/sys\/kernel\/debug \u00a0#modprobe usbmon \u00a0#ls \/sys\/kernel\/debug\/usb\/usbmon 0s 0u 1s 1t 1u 2s 2t 2u 3s 3t 3u 4s 4t 4u 3)Check the USB devices through tshark #sudo tshark -D E.g: #sudo tshark -D tshark: Lua: Error during loading: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[7,6],"_links":{"self":[{"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=\/wp\/v2\/posts\/21"}],"collection":[{"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=21"}],"version-history":[{"count":3,"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=\/wp\/v2\/posts\/21\/revisions"}],"predecessor-version":[{"id":24,"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=\/wp\/v2\/posts\/21\/revisions\/24"}],"wp:attachment":[{"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=21"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=21"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.famlarsson.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=21"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}