22 lines
887 B
Plaintext

$OpenBSD: README-main,v 1.3 2018/09/04 12:53:16 espie Exp $
+-----------------------------------------------------------------------
| Running ${PKGSTEM} on OpenBSD
+-----------------------------------------------------------------------
Packet dissectors (here in Wireshark, and in other programs such as tcpdump)
have a long history of security problems. In Wireshark, these are isolated
from the packet capture code (which must have root privileges) by using a
separate program, dumpcap, to run the capture.
${TRUEPREFIX}/bin/dumpcap has been installed setuid root, with read/execute
access granted only to users in the _wireshark group. For normal interactive
use of Wireshark, add your username to this group:
usermod -G _wireshark username
If you will only run Wireshark offline on files captured using tcpdump -w,
this step is not necessary.
DO NOT RUN WIRESHARK AS ROOT!