From the command line
1 | sudo apt-get install wireshark |
Once the process completes, wireshark will be installed. The only problem is that if you open the wireshark application, there will not be any physical eth(N) devices to sniff. So how do we remedy this?
Open the application ‘Main Menu’

Select wireshark properties

We need to change the command from this

To this

And what is the reason? Well the ethernet or wireless devices we are after are owned by root. So if we tack on the gksudo command to the front of the wireshark init command, we are effectively opening wireshark as root. With all the implied responsibilities and permissions, make sense?

