how Can I remove pcap header from pcap file

asked 2018-01-24

saadouna2402

I want to remove the pcap header from my recorded pcap file to have a binary Ethernet starting with dest. MAC address

1 Answer

answered 2018-01-24

sindy

updated 2018-01-24 15:41:46 +0000

For each individual packet, you may select any item in the packet dissection pane (clicking on the packet in packet list pane is not enough) and then use File->Export Packet Bytes to save the raw contents of the packet into a file.

Saving multiple packets into a signle file would make little sense even if you did that using some scrip parsing the pcap format because the length is not part of the packet data for all Ethernet packets (or it is rather an exception nowadays to have it there) so it would be difficult to parse such file.

I don't know why but I cannot select the option (export packet bytes) I can see it under Files but I cannot choose it

saadouna2402 ( 2018-01-24 15:49:00 +0000 )

Have you loaded a capture file?

grahamb ( 2018-01-24 16:10:29 +0000 )

yes I have

saadouna2402 ( 2018-01-24 16:20:42 +0000 )

As I wrote - it is not enough to select the packet in the packet list. After doing so, you must also click anywhere into the packet dissection pane (where the contents of the selected packet is displayed in detail) to select any line in there. After doing so, the choice in the File menu becomes available. Note for futurre: it may be a bug so in newer versions this may not be necessary any more.

sindy ( 2018-01-24 19:35:59 +0000 )

Asked: 2018-01-24

