ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 5228] tshark: Couldn't load module /opt/iexpress/wireshark

Date: Fri, 17 Sep 2010 02:04:43 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5228

--- Comment #4 from Guy Harris <guy@xxxxxxxxxxxx> 2010-09-17 02:04:20 PDT ---
When you say "I have the same issue as root", are you referring to the issue
mentioned in the title of the bug, or the inability to capture?  The two are
100% completely unrelated.

TShark (and Wireshark) do not directly capture traffic; they run dumpcap to
capture the traffic.  dumpcap is, if it's not set-UID, run with the same
effective user ID as the one TShark or Wireshark are running with when they
start dumpcap - and TShark, at least, surrenders any set-UID and set-GID
privileges it has before starting dumpcap.

If you're running it as root because you've used "su", for example, tshark
shouldn't think it's running with elevated privileges, in the sense of its
effective user ID being different from its real user ID, so it shouldn't
relinquish any privileges.

What is printed if, at the

@@@:root root>

prompt, you run the "id" command?

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.