Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Passwordlist in Wireshark - User feedback wanted

From: Jasper Bongertz <jasper@xxxxxxxxxxxxxx>
Date: Sun, 16 Jun 2019 18:52:13 +0200
Title: Re: [Wireshark-dev] Passwordlist in Wireshark - User feedback wanted

Hi

There is a patch currently waiting for inclusion. It would allow for dissectors to easily make credentials (username/password) available and present them in a tool window in Wireshark.

The main concern here is, that this could lead companies, evaluating Wireshark to be used within  the company, to deny the use of the program, due to wrongly identifying Wireshark as a hacking tool.

We would like your feedback on that topic

kind regards
Roland

Hi,

I have seen at least three occasions where the fact that credentials were that easily accessed with a network analysis tool has resulted in a ban of that exact tool by upper management. In one case this affected a freshly bought license of Clearsight, which immediately after receiving the product ended up in a safe under lock and key, never again to see the light of day.

It may sound weird but this is one case of the typcail "what they don't know doesn't bother them". If this function is added some people will suddenly realize the potential that they are currently unaware of, so it's quite possible that Wireshark will be banned when it is currently fine to use it (in enterprise network that usually means admins only, anyway).

Cheers,
Jasper