Comment #2 from Guy Harris <guy@xxxxxxxxxxxx> 2010-05-19
Another alternative would be to have TShark run dumpcap with sudo and have
Wireshark run it with the GUI equivalent of sudo, although that's trickier as
you want it to run with an *effective* UID of root but with the rest of the
credentials being those of the user, so it can relinquish its root privileges
ASAP and have only the user's credentials when creating capture files.

