Capture Filter VS. Display Filter
The other day I did an experiment. I wanted to see what would happen if I attached a bridged VM to a public network and have an FTP server running.
I only had port 21 open on the firewall and the FTP server was read only (anonymous/anonymous).
I wanted to see how long it would take for someone to connect to my FTP server.
It took no time at all and I had people downloading my garbage text files. ( I am going to be writing another article about my findings and lessons learned through this activity)
However this article is not about people's inherit drive towards voyeurism. It's about how I optimized my use of Wireshark to watch the traffic interacting with the server.