I have Wireshark and have used tcpdump, but I was wondering if there was a nice GUI to capture and view packets on the Mac. Ideally, something that is protocol aware, so that it knows how to break up an HTTP request, is able to show SMTP information in a cleaner way than a tcp dump. I know there are a number of HTTP specific tools that fit this bill, but I'm looking for something that is more general.
Asked
Active
Viewed 4.1k times
3 Answers
8
Just to make sure you're not missing the obvious...you're aware that Wireshark does have a nice GUI, and is protocol aware? And has simple analysis features like "Follow TCP Stream" that making analyzing SMTP (and other text-based protocol transactions) so much easier?
Screenshots are here.
larsks
- 4,053
- 28
- 36
-
I totally agree. For example CocoaPacketAnalyzer from http://www.tastycocoabytes.com/cpa/ might look better for some, but it's so much harder to do proper filtering once one knows what Wireshark can do. – Arjan Nov 29 '09 at 20:29
-
Yes. I'm really looking for alternatives to Wireshark, though with a similar set of features. I can usually get Wireshark to do what I need, but it always takes a while to get there, especially if I haven't used it in a while. I was hoping for something simpler to use, even if a bit less powerful. – Tim Nov 29 '09 at 20:36
-
3to be clear wireshark has a crappy GUI – Ben Glasser Aug 07 '14 at 23:25
4
There are quite a few. The search on macupdate turns up some of them:
Georg Schölly
- 1,248
- 5
- 18
- 36
-
1Packet Peeper looks to be a dead project… As of Sept 1011, there has been no update since 2008. – Paul Wagland Sep 23 '11 at 19:44
-
-
Please bear in mind that he couldn't have known that back in September 1011 ;) – OMA Apr 05 '21 at 03:52
3
I'm a big fan of Charles, which isn't exactly a packet sniffer but does the same thing by using an internal proxy. It has a fantastic GUI and is extremely intuitive. Unfortunately, it's also $50, but has a 30-day trial.
Zac
- 183
- 5
-
1[HTTP Scoop](http://tuffcode.com/) might be a cheaper alternative. – Daniel Beck Jan 23 '12 at 19:45
-
2Note that both Charles and HTTP Scoop are HTTP-only (you won't be able to see packets at TCP/IP/etc level). – ivanzoid Jan 10 '13 at 08:06
-