Wireshark – Filter the Wireless Hosted Network (Win7/8/10)

wireshark

I was thinking about capturing iPhone traffic.

I have created a hosted network to which I can connect my iPhone. I'm able to filter the traffic for server IP addresses which are known, such as Google, Facebook etc. (ping <address>)

The problem is that I have to monitor the ethernet connection on my PC, and my PC gets a lot of background ethernet actions. Is it somehow possible to just display the activity from the hosted network?

P.S.: The IP address from which the packages my iPhone sends is the same as my PC's IP address.

Best Answer

According to: https://msdn.microsoft.com/en-us/library/windows/desktop/dd815243%28v=vs.85%29.aspx

Wireless Hosted Networking creates virtual wireless adapters, including a SoftAP adapter.

If that adapter shows up in the list of interfaces Wireshark can capture on, choosing the SoftAP adapter instead of the adapter your computer uses for it's Internet connection should narrow down what packets you see and let you see the iPhone's Wi-Fi IP and MAC addresses, which will both be different from your computer's addresses. If you've been capturing on the hosting computer's Internet-facing interface, you're probably seeing the iPhone's traffic after it gets NATed to the same IP and MAC addresses as your computer.

Once you switch which interface you're capturing on, you can filter by the MAC address of your iPhone:

https://ask.wireshark.org/questions/14368/capture-filter-mac

You can find an iPhone's Wi-Fi MAC address in:
Settings: General: About
under "Wi-Fi Address"

You can also filter on the IP address of the iPhone. If you can't figure that address out with a short capture on the AP interface, you can find it by tapping the blue-circled "i" next to the SSID (network name) of your hosted Wi-Fi in Settings: Wi-Fi.

Related Topic