?
Solved

Interrogating Wireshark for DNS queries/responses

Posted on 2014-10-12
4
Medium Priority
?
1,225 Views
Last Modified: 2014-10-19
Heyas,

Are there any other commands inside Wireshark other than 'dns.resp.addr' I could use to find what DNS addresses are being requested. My reason for doing this is that I am trying to exclude Apple traffic from my proxy and I would rather do it via DNS address than exclude whole ip ranges.

Thank you.
0
Comment
Question by:Zack
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 24

Assisted Solution

by:DMTechGrooup
DMTechGrooup earned 1000 total points
ID: 40378038
How many computers are you tying to scan for?  This might be something worth looking at.

http://www.nirsoft.net/utils/dns_query_sniffer.html

Also

http://wiki.wireshark.org/DNS
0
 
LVL 57

Expert Comment

by:giltjr
ID: 40378140
Just be aware that dns.resp.addr is only supported in wireshark version 1.4.0 to 1.10.10.  After 1.10.10 it does not exist.

What proxy are you running?
0
 
LVL 64

Accepted Solution

by:
btan earned 1000 total points
ID: 40378940
You can use the -T fields switch and print "dns.qry.name" with tshark.
http://www.netresec.com/?page=Blog&month=2012-06&post=Extracting-DNS-queries
(sidenote - There is a DNS tab in NetworkMiner, which displays a nice list of all DNS queries and responses in a pcap file.)

or You can also use  tshark -2 -R "dns && (dns.flags.response == 0) && ! dns.response_in"
https://ask.wireshark.org/questions/18487/filter-dns-queries-without-matched-responses
0
 

Author Closing Comment

by:Zack
ID: 40391360
Cheers guys those apps are awesome.
0

Featured Post

WatchGuard's M Series Appliances - Miecom Approved

WatchGuard's newest M series appliances were put to the test by Miercom.  We had great results and outperformed all of our competitors in both stateless and stateful traffic throghput scenarios! Ready to see how your UTM appliance stacked up? Download the Miercom Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question