Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

You're using a keyboard! How quaint!


computers / comp.mobile.android / Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

SubjectAuthor
* Network packet capture app (like Wireshark) for non-rooted phoneNY
+- Re: Network packet capture app (like Wireshark) for non-rooted phoneAndy Burns
+* Re: Network packet capture app (like Wireshark) for non-rooted phoneNY
|+- Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.NY
|`* Re: Network packet capture app (like Wireshark) for non-rooted phoneAndy Burns
| `* Re: Network packet capture app (like Wireshark) for non-rooted phoneNY
|  +* Re: Network packet capture app (like Wireshark) for non-rooted phonesms
|  |`- Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.Theo
|  +* Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.Theo
|  |`- Re: Network packet capture app (like Wireshark) for non-rooted phoneAndy Burns
|  `- Re: Network packet capture app (like Wireshark) for non-rooted phoneAndy Burns
`- Re: Network packet capture app (like Wireshark) for non-rootedRob

1
Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19818&group=comp.mobile.android#19818

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!aioe.org!feeder1.feed.usenet.farm!feed.usenet.farm!newsfeed.xs4all.nl!newsfeed8.news.xs4all.nl!border2.nntp.ams1.giganews.com!nntp.giganews.com!buffer2.nntp.ams1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Mon, 30 Aug 2021 13:55:31 -0500
Date: Mon, 30 Aug 2021 19:55:30 +0100
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.0.3
Newsgroups: comp.mobile.android
Content-Language: en-GB
From: me...@privacy.net (NY)
Subject: Network packet capture app (like Wireshark) for non-rooted phone
(Android 8.0.0)
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Antivirus: AVG (VPS 210830-0, 30/8/2021), Outbound message
X-Antivirus-Status: Clean
Message-ID: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
Lines: 42
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-9EjpFH9o1bhUBH1aKI81w0dtuB9Axt594vOW852bLrSVw+vy/i01DuPANTzAUV8+JEDTP1fH4wE31KR!OrctY0OmsLLXLNBH6gkoxSD+kcaR69UUS0IrYmgoNEW9VixF6tnwSRjB15Y/LfY1xHPNPhDcQl1+!d00ZPXHrK3ljrO4Zt9IMtxpr
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 3202
 by: NY - Mon, 30 Aug 2021 18:55 UTC

I'm trying to investigate a bizarre problem: none of the browsers
(Firefox, Google Chrome, Dolphin) on my Android 8 (Samsung Galaxy S7)
phone can access a specific web site (my own site of weather station
data, hosted by GoDaddy). This worked perfectly until a few days ago.
The symptom is that the browser usually times out. Very occasionally it
works fine, but only for a couple of pages on the site before failing
again. I can still access the site from browsers on Windows, Linux and iPad.

What is weird is that it fails over my wifi/VDSL connection, but works
over my Vodafone mobile internet connection.

I'd like to see what traffic (eg HTTP GET) the browser is sending, and
what response from the server is received, and compare these with
corresponding traffic for accessing the site from Windows or Linux -
which still work perfectly.

I gather that a lot of Wireshark-equivalents need the phone to be
rooted. I've found a few which don't: Packet Capture (Grey Shirts) and
PCAPDroid (Emanuele Faranda). However neither seem to work.

Both apps show traffic to/from the IP, as determined by NSLOOKUP on
Windows), so the DNS name-to-IP mapping is working.

Packet Capture shows traffic between Dolphin (for example) and the IP
address of my site. But it reports "no data". It does that for most
network traffic, including a successful browse to Facebook's web page as
a test.

PCAPDroid shows Dolphin sending a 60-byte packet out and getting no
response - but it won't show the data in the packet (even as hex), nor
can I see a way to export a capture to a PCAP file which I could analyse
in Wireshark on a PC.

So, is there any Android packet-capture software that actually works,
which will see the packets (maybe display them as hex to prove that it's
worked!) and will export to PCAP file for Wireshark to analyse.

I want a network trace that I can send to GoDaddy and maybe my ISP to
say "this is what I'm sending and (not) receiving - what's going on?".

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<ip4o51Fknn5U1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19819&group=comp.mobile.android#19819

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: use...@andyburns.uk (Andy Burns)
Newsgroups: comp.mobile.android
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone
(Android 8.0.0)
Date: Mon, 30 Aug 2021 19:59:44 +0100
Lines: 8
Message-ID: <ip4o51Fknn5U1@mid.individual.net>
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net ubu+W2V4InR5Sbr6YDo/Xgrj3cDkLTLMGK9PVZBtfae2UxMWw9
Cancel-Lock: sha1:OdB/LKmYoCYrLe3FtE68emBhOfw=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.0.3
Content-Language: en-GB
In-Reply-To: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
 by: Andy Burns - Mon, 30 Aug 2021 18:59 UTC

NY wrote:

> I want a network trace that I can send to GoDaddy and maybe my ISP to
> say "this is what I'm sending and (not) receiving - what's going on?".

Could you try proxy settings in the browser, to a proxy under your
control, then wireshark it at the proxy? Of course that might "fix" the
problen, which wouldn't help ...

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19821&group=comp.mobile.android#19821

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!border2.nntp.ams1.giganews.com!nntp.giganews.com!buffer2.nntp.ams1.giganews.com!buffer1.nntp.ams1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Mon, 30 Aug 2021 14:43:39 -0500
Date: Mon, 30 Aug 2021 20:43:37 +0100
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.0.3
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone
(Android 8.0.0)
Content-Language: en-GB
Newsgroups: comp.mobile.android
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
From: me...@privacy.net (NY)
In-Reply-To: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Antivirus: AVG (VPS 210830-0, 30/8/2021), Outbound message
X-Antivirus-Status: Clean
Message-ID: <h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
Lines: 18
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-y2kAcXl7Kb1rh65cQnpePazxoJcyS7bPak25nup64sEh1RiBtw822nLqMEp7JZnKKpZDFUv7q4g+lJL!o+WfxaBwpsr+w6ifzpqMIDYor8ot4vnlDWfkH8/97qL7CRlISGFeFsV335Wi7oam9MyTlMT+/yYM!GTwBThFryhleMz/gYbq7Sm7a
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 2126
 by: NY - Mon, 30 Aug 2021 19:43 UTC

On 30/08/2021 19:55, NY wrote:
> So, is there any Android packet-capture software that actually works,
> which will see the packets (maybe display them as hex to prove that it's
> worked!) and will export to PCAP file for Wireshark to analyse.

I've also tried Debug Proxy (Mateus Pinhero) and that doesn't see ANY
traffic from ANY app.

Either I'm missing something very obvious with using these
Wireshark-like packet-capture apps, or they simply don't work on my phone.

I can't use Wireshark on a Windows PC (even if it is connected to the
same wifi as the phone) because my router or my wifi adaptor doesn't
seem to support "promiscuous mode" - ie showing that isn't to or from my
IP address. That's why I need packet-capture on the same device as the
one which is generating the HTTP traffic.

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<sgjcr1$veg$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19822&group=comp.mobile.android#19822

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: me...@privacy.invalid (NY)
Newsgroups: comp.mobile.android
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)
Date: Mon, 30 Aug 2021 20:50:14 +0100
Organization: A noiseless patient Spider
Lines: 2
Message-ID: <sgjcr1$veg$1@dont-email.me>
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk> <h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
Mime-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset="UTF-8";
reply-type=response
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 30 Aug 2021 19:50:57 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="ab4b4d71100c31cae05da1f62bac0f91";
logging-data="32208"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18cjyfBACgo587Z5WMcXYbza1qiElYf5MY="
Cancel-Lock: sha1:Cm/Ri4y4G32wc4w8A7S1hWBGbtg=
X-MimeOLE: Produced By Microsoft MimeOLE V14.0.8089.726
In-Reply-To: <h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
X-Antivirus-Status: Clean
X-Newsreader: Microsoft Windows Live Mail 14.0.8089.726
Importance: Normal
X-Antivirus: Avast (VPS 210830-0, 30/8/2021), Outbound message
X-Priority: 3
X-MSMail-Priority: Normal
 by: NY - Mon, 30 Aug 2021 19:50 UTC

"NY" <me@privacy.net> wrote in message
news:h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk...
> On 30/08/2021 19:55, NY wrote:
>> So, is there any Android packet-capture software that actually works,
>> which will see the packets (maybe display them as hex to prove that it's
>> worked!) and will export to PCAP file for Wireshark to analyse.
>
> I've also tried Debug Proxy (Mateus Pinhero) and that doesn't see ANY
> traffic from ANY app.
>
> Either I'm missing something very obvious with using these Wireshark-like
> packet-capture apps, or they simply don't work on my phone.
>
>
>
> I can't use Wireshark on a Windows PC (even if it is connected to the same
> wifi as the phone) because my router or my wifi adaptor doesn't seem to
> support "promiscuous mode" - ie showing that isn't to or from my IP
> address. That's why I need packet-capture on the same device as the one
> which is generating the HTTP traffic.

Spot the missing word! I meant "showing *traffic* that isn't to or from my
IP address"

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<ip4rqpFlen0U1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19823&group=comp.mobile.android#19823

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: use...@andyburns.uk (Andy Burns)
Newsgroups: comp.mobile.android
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone
(Android 8.0.0)
Date: Mon, 30 Aug 2021 21:02:33 +0100
Lines: 8
Message-ID: <ip4rqpFlen0U1@mid.individual.net>
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
<h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net JiBIXZ2E+oNL/IqOuCynywDPwNtVpSH+cGNtECDOur5kBdsgjO
Cancel-Lock: sha1:4mc2NDDrlHj6aLfGuD81FqZn6vo=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.0.3
Content-Language: en-GB
In-Reply-To: <h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
 by: Andy Burns - Mon, 30 Aug 2021 20:02 UTC

NY wrote:

> I can't use Wireshark on a Windows PC (even if it is connected to the
> same wifi as the phone) because my router or my wifi adaptor doesn't
> seem to support "promiscuous mode"

I meant run a proxy+wireshark on a wired PC ...

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19830&group=comp.mobile.android#19830

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!newsfeed.xs4all.nl!newsfeed7.news.xs4all.nl!border2.nntp.ams1.giganews.com!nntp.giganews.com!buffer2.nntp.ams1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Mon, 30 Aug 2021 16:24:04 -0500
Date: Mon, 30 Aug 2021 22:24:02 +0100
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.0.3
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone
(Android 8.0.0)
Content-Language: en-GB
Newsgroups: comp.mobile.android
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
<h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
<ip4rqpFlen0U1@mid.individual.net>
From: me...@privacy.net (NY)
In-Reply-To: <ip4rqpFlen0U1@mid.individual.net>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Antivirus: AVG (VPS 210830-0, 30/8/2021), Outbound message
X-Antivirus-Status: Clean
Message-ID: <isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk>
Lines: 28
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-YOxyf+cXC4EBGcr970RIUUZwReHf9hss3TBrZk9Y/hl8wykjtVx1LoBHHWRJAD3G5t16bMR/nfqKeh+!jLydM0DH+avI4MYVgGVovPfr6VY6RiqhF55HqDH9dK/dCfpz6D1ccmiuKI28+B46utyp/WKIYooj!bzLF22Ada+VO02D09FG0EICK
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 2615
 by: NY - Mon, 30 Aug 2021 21:24 UTC

On 30/08/2021 21:02, Andy Burns wrote:
> NY wrote:
>
>> I can't use Wireshark on a Windows PC (even if it is connected to the
>> same wifi as the phone) because my router or my wifi adaptor doesn't
>> seem to support "promiscuous mode"
>
> I meant run a proxy+wireshark on a wired PC ...

Bugger!!!!

I set up CCproxy on my Windows PC and ran a Wireshark trace. I
configured Firefox Nightly (the development version which allows it to
use a proxy) to use my Windows PC as a SOCKS proxy. And I saw the HTTP
traffic beautifully, filtering on conversations between phone and
Windows PC.

Only problem - as you predicted earlier, this made it sodding-well work
:-( (You are allowed to laugh and say "told you so"!)

It's as if when the phone is using its own direct connection, something
happens to the HTTP traffic to/from the web server. But if it goes via
the Windows proxy, it works - probably because it is using the same
mechanism that a Windows browser on the PC uses, and that works fine.

So what is it about my site (http://goosebears.co.uk/weather) which is
breaking access from Android, when all other sites that I use work fine.
And why has it only started happening in the last few days?

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<sgjks9$mg3$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19836&group=comp.mobile.android#19836

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!aioe.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: scharf.s...@geemail.com (sms)
Newsgroups: comp.mobile.android
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone
(Android 8.0.0)
Date: Mon, 30 Aug 2021 15:08:07 -0700
Organization: A noiseless patient Spider
Lines: 13
Message-ID: <sgjks9$mg3$1@dont-email.me>
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
<h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
<ip4rqpFlen0U1@mid.individual.net>
<isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 30 Aug 2021 22:08:09 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="cbe074af8b336647e2db5a209cff9250";
logging-data="23043"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19Cf1RcyqwmCB5xoGPj20ez"
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
Cancel-Lock: sha1:GLD86tdWUKBklXePZOOXIClwrxA=
In-Reply-To: <isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk>
Content-Language: en-US
 by: sms - Mon, 30 Aug 2021 22:08 UTC

On 8/30/2021 2:24 PM, NY wrote:

<snip>.

> So what is it about my site (http://goosebears.co.uk/weather) which is
> breaking access from Android, when all other sites that I use work fine.
> And why has it only started happening in the last few days?

I've seen non-secure web sites (http instead of https) sometimes cause
problems.

I don't think that there is a packet capture app that works on
non-rooted Android. I've tried them and they don't display any data.

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<Reh*Sx1sy@news.chiark.greenend.org.uk>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19837&group=comp.mobile.android#19837

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!paganini.bofh.team!newsfeed.xs3.de!io.xs3.de!nntp-feed.chiark.greenend.org.uk!ewrotcd!.POSTED!not-for-mail
From: theom+n...@chiark.greenend.org.uk (Theo)
Newsgroups: comp.mobile.android
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)
Date: 30 Aug 2021 23:12:03 +0100 (BST)
Organization: University of Cambridge, England
Lines: 14
Message-ID: <Reh*Sx1sy@news.chiark.greenend.org.uk>
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk> <h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk> <ip4rqpFlen0U1@mid.individual.net> <isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk>
NNTP-Posting-Host: chiark.greenend.org.uk
X-Trace: chiark.greenend.org.uk 1630361525 13856 212.13.197.229 (30 Aug 2021 22:12:05 GMT)
X-Complaints-To: abuse@chiark.greenend.org.uk
NNTP-Posting-Date: Mon, 30 Aug 2021 22:12:05 +0000 (UTC)
User-Agent: tin/1.8.3-20070201 ("Scotasay") (UNIX) (Linux/3.16.0-11-amd64 (x86_64))
Originator: theom@chiark.greenend.org.uk ([212.13.197.229])
 by: Theo - Mon, 30 Aug 2021 22:12 UTC

NY <me@privacy.net> wrote:
> So what is it about my site (http://goosebears.co.uk/weather) which is
> breaking access from Android, when all other sites that I use work fine.
> And why has it only started happening in the last few days?

As I posted on your thread in uk.telecom.broadband, your webserver is
telling your phone browser to upgrade to HTTP/2 over TLS, but the TLS
certificate on the server is broken.

My guess when you're using a proxy is that it doesn't support HTTP/2 or
isn't passing the Upgrade: header, so the upgrade doesn't happen and it
accesses the cleartext HTTP/1.1 version which works.

Theo

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<Reh*TI1sy@news.chiark.greenend.org.uk>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19839&group=comp.mobile.android#19839

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!aioe.org!nntp.terraraq.uk!nntp-feed.chiark.greenend.org.uk!ewrotcd!.POSTED!not-for-mail
From: theom+n...@chiark.greenend.org.uk (Theo)
Newsgroups: comp.mobile.android
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)
Date: 30 Aug 2021 23:59:03 +0100 (BST)
Organization: University of Cambridge, England
Lines: 15
Message-ID: <Reh*TI1sy@news.chiark.greenend.org.uk>
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk> <h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk> <ip4rqpFlen0U1@mid.individual.net> <isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk> <sgjks9$mg3$1@dont-email.me>
NNTP-Posting-Host: chiark.greenend.org.uk
X-Trace: chiark.greenend.org.uk 1630364345 10087 212.13.197.229 (30 Aug 2021 22:59:05 GMT)
X-Complaints-To: abuse@chiark.greenend.org.uk
NNTP-Posting-Date: Mon, 30 Aug 2021 22:59:05 +0000 (UTC)
User-Agent: tin/1.8.3-20070201 ("Scotasay") (UNIX) (Linux/3.16.0-11-amd64 (x86_64))
Originator: theom@chiark.greenend.org.uk ([212.13.197.229])
 by: Theo - Mon, 30 Aug 2021 22:59 UTC

sms <scharf.steven@geemail.com> wrote:
> I don't think that there is a packet capture app that works on
> non-rooted Android. I've tried them and they don't display any data.

This one claims to set up a VPN through which you can run your traffic,
and then capture it into a .pcap file you can load into desktop Wireshark:
https://play.google.com/store/apps/details?id=com.egorovandreyrm.pcapremote

Not tested it, but it's how I'd expect a non-root capture app to work. This
is how non-root firewalling works and the idea is the same.

Watch the video on the listing and it's doing exactly what the OP wants to
do.

Theo

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<slrnsirpri.g48.nomail@xs9.xs4all.nl>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19864&group=comp.mobile.android#19864

  copy link   Newsgroups: comp.mobile.android
Newsgroups: comp.mobile.android
From: nom...@example.com (Rob)
Subject: Re: Network packet capture app (like Wireshark) for non-rooted
phone (Android 8.0.0)
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
User-Agent: slrn/1.0.3 (Linux)
Message-ID: <slrnsirpri.g48.nomail@xs9.xs4all.nl>
Organization: KPN B.V.
Date: Tue, 31 Aug 2021 10:25:22 +0200
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!feed.abavia.com!abe002.abavia.com!abp003.abavia.com!news.kpn.nl!not-for-mail
Lines: 35
Injection-Date: Tue, 31 Aug 2021 10:25:22 +0200
Injection-Info: news.kpn.nl; mail-complaints-to="abuse@kpn.com"
 by: Rob - Tue, 31 Aug 2021 08:25 UTC

NY <me@privacy.net> wrote:
> I'm trying to investigate a bizarre problem: none of the browsers
> (Firefox, Google Chrome, Dolphin) on my Android 8 (Samsung Galaxy S7)
> phone can access a specific web site (my own site of weather station
> data, hosted by GoDaddy). This worked perfectly until a few days ago.
> The symptom is that the browser usually times out. Very occasionally it
> works fine, but only for a couple of pages on the site before failing
> again. I can still access the site from browsers on Windows, Linux and iPad.
>
> What is weird is that it fails over my wifi/VDSL connection, but works
> over my Vodafone mobile internet connection.

This is normally caused by a too agressive firewall on your server,
e.g. as directed by the clueless "expert" Steve Gibson.

When your server firewall "blocks all ICMP" ("because ping is evil" or
"because you want to be stealth!") and your internet connection has
a maximum packet size (MTU) of less than 1500 bytes, you get this
exact problem.

An MTU of less than 1500 bytes is usually an issue when the internet
connection uses PPPoE as a link protocol (common with DSL lines).

The server will send packets of 1500 bytes, and the ISP will return
an ICMP packet saying "hey that is too big, maximum is 1492".
But your firewall drops the packet, your server software never gets
the message, and the connection stalls.

So, do not block ICMP. Also not when Steve recommends it.

To work around it, in some internet routers you can setup "TCP MSS
clamping", i.e. the router modifies the connection setup packet sent
from your phone to the server to indicate that you cannot receive
large packets. That fixes it for cases as you describe.

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<ip67quFtd2mU1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19865&group=comp.mobile.android#19865

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: use...@andyburns.uk (Andy Burns)
Newsgroups: comp.mobile.android
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone
(Android 8.0.0)
Date: Tue, 31 Aug 2021 09:33:33 +0100
Lines: 14
Message-ID: <ip67quFtd2mU1@mid.individual.net>
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
<h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
<ip4rqpFlen0U1@mid.individual.net>
<isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net TAMi1LLWC6DU0iCG4FNgUw/2SqYN02o5kfZ68Gp77aovl1XNEp
Cancel-Lock: sha1:6n5JiU1wfaXvYICu2SVnJvuW84I=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.0.3
Content-Language: en-GB
In-Reply-To: <isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk>
 by: Andy Burns - Tue, 31 Aug 2021 08:33 UTC

NY wrote:

> So what is it about my site (http://goosebears.co.uk/weather) which is
> breaking access from Android

Well, as I said the other day, it's not broken for me

Google Pixel3 with android 11
using current Firefox
over Wifi to my Vigor router
via VDSL to Plusnet

Anything else I can test?

Re: Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

<ip6801Ftd2mU2@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=19866&group=comp.mobile.android#19866

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: use...@andyburns.uk (Andy Burns)
Newsgroups: comp.mobile.android
Subject: Re: Network packet capture app (like Wireshark) for non-rooted phone
(Android 8.0.0)
Date: Tue, 31 Aug 2021 09:36:16 +0100
Lines: 7
Message-ID: <ip6801Ftd2mU2@mid.individual.net>
References: <kdidnVuykIg-tLD8nZ2dnUU78X3NnZ2d@brightview.co.uk>
<h7udnaGI_fh2qbD8nZ2dnUU78bXNnZ2d@brightview.co.uk>
<ip4rqpFlen0U1@mid.individual.net>
<isCdnThNS6Dp0bD8nZ2dnUU78cPNnZ2d@brightview.co.uk>
<Reh*Sx1sy@news.chiark.greenend.org.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net ZrFe0EkoEaZlT2llyLbA5A6/dZcqN4eQQK//eoUlOygxghwd5E
Cancel-Lock: sha1:LuDxiZlkPfawIBtSAP4f28jUFDg=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.0.3
Content-Language: en-GB
In-Reply-To: <Reh*Sx1sy@news.chiark.greenend.org.uk>
 by: Andy Burns - Tue, 31 Aug 2021 08:36 UTC

Theo wrote:

> your webserver is telling your phone browser to upgrade to HTTP/2
> over TLS

It stays as http:// with my desktop and android firefoxes


computers / comp.mobile.android / Network packet capture app (like Wireshark) for non-rooted phone (Android 8.0.0)

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor