Remote ssh capture does not work on Windows 10

Hi all,

It used to work, but with some recent updates, it broke. Wireshark and router FW were updated, so not 100% on which side the fault is, the user maybe :)

Error message in the link below:

It complains about: Unable to write to standard output: The pipe is being closed.

Any help?

Thanks, Myky

What is output of wireshark -v?

Chuckc ( 2021-02-03 19:36:19 +0000 )

Sorry for not providing that info initially. Please see below:

C:\Program Files\Wireshark>

Wireshark 3.4.3 (v3.4.3-0-g6ae6cd335aa9)

It's the latest.

myky ( 2021-02-03 20:01:25 +0000 )

Similar question - Windows remote ssh capture not getting packets

1. For test, send output to a file (plink.exe ..... > test.pcap) then open the file with Wireshark.
2. Has this syntax working in the past without -w - option for tcpdump?

What a magic command right click > run as administrator )) When l started my CMD with admin rights, boom, l can see packets.

Thanks Chuckc!

myky ( 2021-02-03 22:24:34 +0000 )

You could also use the built-in extcap (optional in the installer) sshdump to capture over an ssh connection. Note that on Windows, the ssh library used only supports ssh with username and password.

grahamb ( 2021-02-04 09:25:30 +0000 )

Thanks. Never heard about that option. Will keep it in my tshoot box.

myky ( 2021-02-04 09:52:06 +0000 )

