Ask Your Question

Data change after saving

asked 2020-08-27 09:07:01 +0000

zohar gravatar image

Hi I using udp.port==5556 filter. Mark the relevant files ->Click File -> Export Spesific Packets -> Selected pakets . After I saved the packets I opened the new file and the display has change and not look the same . Protocol has changed and in the new file and also the Info not dispaly the same . What can I do ? Thanks

edit retag flag offensive close merge delete


You don't say what protocol is running on udp 5556, but some protocols require information from traffic running on other ports to describe how the actual traffic is to be dissected.

By filtering you may have removed that "setup" information.

What protocol are you looking at? Can you share the capture on a public share, e.g. Google Drive, DropBox etc. and post a link to it back here?

grahamb gravatar imagegrahamb ( 2020-08-27 09:26:18 +0000 )edit

1 Answer

Sort by ยป oldest newest most voted

answered 2020-08-27 11:01:16 +0000

grahamb gravatar image

You have fragmented IP packets and are only exporting the final frame (as they are the marked ones) where the complete IP packet is reassembled and when you subsequent load that capture you only have the trailing IP fragments which can't be made into UDP datagrams.

To get the capture you require, set the display filter appropriately, e.g. udp.port == 5556 and then go to "Export Specified Packets..." and choose "All packets" and "Displayed" and you will get all the IP fragments.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools


Asked: 2020-08-27 09:07:01 +0000

Seen: 417 times

Last updated: Aug 27 '20