Why am I able to open Wireshark and capture packets in macOS without root privileges?
12
votes
1
answer
5654
views
As far as I know, capturing packets using Wireshark requires root/administrator privileges. In Windows, it prompts for UAC elevation and runs with administrative privileges. The same thing in Ubuntu; it prompts for a password to authorize access before showing me the interfaces.
However, in macOS, there is no authorization required. I don't have to enter a password. Instead, Wireshark is directly showing me the interfaces and I am able to capture packets.
How is Wireshark able to do this on macOS? What is special about macOS that allows interfaces and packets to be monitored *without* administrative access?
Asked by scipsycho
(359 rep)
Feb 27, 2019, 12:04 PM
Last activity: Apr 2, 2019, 07:09 AM
Last activity: Apr 2, 2019, 07:09 AM