Hello All,

I want to search on the Data field of a TCP packet where I can search on a data byte pattern not a data string, Is this possible, if so how?

Regards

B

asked 13 Sep '11, 09:14

Baz's gravatar image

Baz
16223
accept rate: 0%

edited 13 Sep '11, 10:16

helloworld's gravatar image

helloworld
2.8k21940


Yes, you can use display filter syntax to search for a particular byte sequence. Here's an example display filter to find {A1,B2,C3,D4} anywhere in tcp.data:

tcp.data contains A1:B2:C3:D4
link

answered 13 Sep '11, 10:15

helloworld's gravatar image

helloworld
2.8k21940
accept rate: 27%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×91

Asked: 13 Sep '11, 09:14

Seen: 12,226 times

Last updated: 13 Sep '11, 10:16

powered by OSQA