Hello, I need to modify a pcap file. For example, I need to edit the IP address, timestamp, URL, ... fields. How can I do it? Do I have to write a new software application, or is one available in the network?

Thanks Paolino

asked 17 Feb '12, 05:25

Paolino's gravatar image

Paolino
1111
accept rate: 0%

edited 26 Feb '12, 20:37

cmaynard's gravatar image

cmaynard ♦
6.2k725106


What you need are tools that are usually used for anonymization and/or packet replay of trace files. You might want to take a look at tcprewrite, bittwiste, pktanon and other tools. You can also download the Sharkfest 2011 presentation (A-11) I did at the retrospective page:

http://sharkfest.wireshark.org/sharkfest.11/index.html

link

answered 17 Feb '12, 05:31

Jasper's gravatar image

Jasper ♦
16.1k338212
accept rate: 17%

edited 17 Feb '12, 05:35

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×112
×4

Asked: 17 Feb '12, 05:25

Seen: 5,037 times

Last updated: 26 Feb '12, 20:37

powered by OSQA