Wireshark and Virtualbox Networking

This is for discussing general topics about how to use VirtualBox.
Post Reply
worksofcraft
Posts: 4
Joined: 9. Aug 2011, 14:04
Primary OS: MS Windows 7
VBox Version: OSE other
Guest OSses: Ubuntu

Wireshark and Virtualbox Networking

Post by worksofcraft »

I want to asses downloads for malicious malware by installing them on a virtual machine and then using wireshark on the host computer or in another virtual machine to monitor network traffic.

I can't seem to make it work: The packets to and from the virtual machine seem to be invisible. :cry:

Just wondering if anyone else is using virtual machines for this purpose and if they can help me get it working please :)
kebabbert
Volunteer
Posts: 321
Joined: 31. May 2008, 10:00
Primary OS: OpenSolaris 11
VBox Version: OSE other
Guest OSses: WinXP, RedHat, Ubuntu

Re: Wireshark and Virtualbox Networking

Post by kebabbert »

worksofcraft wrote:I want to asses downloads for malicious malware by installing them on a virtual machine and then using wireshark on the host computer or in another virtual machine to monitor network traffic.

I can't seem to make it work: The packets to and from the virtual machine seem to be invisible. :cry:

Just wondering if anyone else is using virtual machines for this purpose and if they can help me get it working please :)
Are you using "Bridged NIC"?
worksofcraft
Posts: 4
Joined: 9. Aug 2011, 14:04
Primary OS: MS Windows 7
VBox Version: OSE other
Guest OSses: Ubuntu

Re: Wireshark and Virtualbox Networking

Post by worksofcraft »

kebabbert wrote: Are you using "Bridged NIC"?
Yes. I want it to look as much as possible like a real machine plugged into a simple network hub.
The snap shot facilities of Virtualbox are essential to restore it to a known state for each test.

I found similar ideas for this on the internet but none with a solution yet :|
BillG
Volunteer
Posts: 5106
Joined: 19. Sep 2009, 04:44
Primary OS: MS Windows 10
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: Windows 10,7 and earlier
Location: Sydney, Australia

Re: Wireshark and Virtualbox Networking

Post by BillG »

That should work if the guest is using bridged mode. I regularly use Network Monitor on the host to monitor traffic and the vms all behave normally. I can't see why wireshark would be any different.

Here is an extract from the output. Win7x64 is a virtual machine.
Netmon.png
Bill
worksofcraft
Posts: 4
Joined: 9. Aug 2011, 14:04
Primary OS: MS Windows 7
VBox Version: OSE other
Guest OSses: Ubuntu

Re: Wireshark and Virtualbox Networking

Post by worksofcraft »

BillG wrote:That should work if the guest is using bridged mode. I regularly use Network Monitor on the host to monitor traffic and the vms all behave normally. I can't see why wireshark would be any different.
:o

You are right, Microsoft Network Monitor works just fine!
It must be a wireshark problem... oh well I will start using Network Monitor then, thanks :)
Post Reply