Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

I had to update wireshark, and if I remember correctly, a pop up asked me about root permission or something. I clicked "NO" and I think this is my problem.

The Wireshark 3.2.x disk image is a drag-install image, so you won't get the pop-up at installation time.

If, however, you haven't installed the "ChmodBPF' component in the image, if you start up Wireshark 3.2.7, there will be, on the main Wireshark screen, above the list of network devices, a message "You don't have permission to capture. You can install ChmodBPF to fix this". "install ChmodBPF to fix this" is in blue and is underlined; this indicates that you can click on it and, if you do, it will start up the ChmodBPF installer; run the installer, by clicking "Continue" and continuing through the process.

If you haven't installed ChmodBPF, and you try to start a capture, you will get a pop-up that says

The capture session could not be initiated on interface 'XXX' (You don't have permission to capture on that device).

Please check to make sure that you have sufficient permissions.

If you installed Wireshark using the package from wireshark.org, Try re-installing it and checking the box for the "Set capture permissions on startup" item.

There's no "Yes" vs. "No" choice for that pop-up, there's only an "OK" choice. (Ignore the last paragraph of the pop-up; it's out of date. I'll look at fixing that - along with the incorrect capitalization of "try".)

What you should do is, as per the above, start up Wireshark 3.2.7 and click on the "Install ChmodBPF to fix this" link; that will start the ChmodBPF installer - run through the installation process.

I had to update wireshark, and if I remember correctly, a pop up asked me about root permission or something. I clicked "NO" and I think this is my problem.

The Wireshark 3.2.x disk image is a drag-install image, so you won't get the pop-up at installation time.

If, however, you haven't installed the "ChmodBPF' component in the image, if you start up Wireshark 3.2.7, there will be, on the main Wireshark screen, above the list of network devices, a message "You don't have permission to capture. You can install ChmodBPF to fix this". "install ChmodBPF to fix this" is in blue and is underlined; this indicates that you can click on it and, if you do, it will start up the ChmodBPF installer; run the installer, by clicking "Continue" and continuing through the process.

If you haven't installed ChmodBPF, and you try to start a capture, you will get a pop-up that says

The capture session could not be initiated on interface 'XXX' (You don't have permission to capture on that device).

Please check to make sure that you have sufficient permissions.

If you installed Wireshark using the package from wireshark.org, Try re-installing it and checking the box for the "Set capture permissions on startup" item.

There's no "Yes" vs. "No" choice for that pop-up, there's only an "OK" choice. (Ignore the last paragraph of the pop-up; it's out of date. I'll look at fixing that - along with the incorrect capitalization of "try".)

What you should do is, as per the above, start up Wireshark 3.2.7 and click on the "Install ChmodBPF to fix this" link; that will start the ChmodBPF installer - run through the installation process.

(This is not unique to Catalina; you need ChmodBPF on all versions of macOS, even the versions that were called "Mac OS X" or "OS X" when they were released.)