2021-07-29 08:44:12 +0000 | received badge | ● Supporter (source) |
2021-07-27 07:09:33 +0000 | marked best answer | Filter for empty SMPP messages Hi, I am trying to construct a filter for incoming smpp messages that are empty and are the first message in. From the logs, when the smpp packet is decoded, I have messages that look like this: And the values (I think) of interest, should be the "'data_coding': 15", and the ''short_message': None' parts. But I am having trouble matching these in a Wireshark filter. So far I've come up with permutations of this type: 'smpp.data_coding eq 15 and smpp.ussd_service_op eq 0x05 and smpp.sm_default_msg_id eq 0' Which unfortunately keep catching messages that do not have empty or null content. Please can someone help me correct or properly define this? If I could understand how properly to use the optional parameters values as well, would be a great help. Thanks! |
2021-07-26 20:17:09 +0000 | commented answer | Filter for empty SMPP messages Oh yes! Unfortunately I don't have points enough to accept my own answer. |
2021-07-26 20:15:36 +0000 | marked best answer | Filtering odd-length binary data Hi! Im struggling with extracting information from Wireshark. I need to be able to differentiate between correctly formatted tcp packet data, and incorrectly (odd-length) data that an application is receiving. For example, correctly formatted data from app logs looks like this: Incorrectly formatted data looks like this (also from the logs): How can I filter out and present the packets that contain the odd length strings, from the tcp data? With hindsight, I guess I am asking how do I write a display filter to capture binary data that looks contains this: Thanks, I hope I am clear! |
2021-07-26 20:15:36 +0000 | received badge | ● Scholar (source) |
2021-07-26 20:15:31 +0000 | commented answer | Filtering odd-length binary data Oh right thanks a lot |
2021-07-26 18:03:18 +0000 | commented answer | Filtering odd-length binary data Wow, that's exactly what I am trying to show (and what the application is rejecting as odd-length packet). Please how di |
2021-07-26 17:51:52 +0000 | commented answer | Filter for empty SMPP messages Sorry about that :-) Work was/is crazy. Also is crazy is my not wanting to leave anything unanswered, no matter how long |
2021-07-26 17:48:19 +0000 | received badge | ● Editor (source) |
2021-07-26 17:48:19 +0000 | edited question | Filtering odd-length binary data Filtering odd-length binary data Hi! Im struggling with extracting information from Wireshark. I need to be able to dif |
2021-07-26 17:45:33 +0000 | answered a question | Filter for empty SMPP messages smpp.data_coding == 0x0f and smpp.ussd_service_op == 0x05 really helped, with other smpp filtering combinations. |
2021-07-26 17:45:33 +0000 | commented question | Filter for empty SMPP messages Yes it was, and I was able to pull out the SMPP data needed |
2021-07-26 17:45:32 +0000 | asked a question | Filtering odd-length binary data Filtering odd-length binary data Hi! Im struggling with extracting information from Wireshark. I need to be able to dif |
2021-03-18 07:43:56 +0000 | commented question | Filter for empty SMPP messages Its a log from an SMPP client. |
2021-03-16 19:19:21 +0000 | asked a question | Filter for empty SMPP messages Filter for empty SMPP messages Hi, I am trying to construct a filter for incoming smpp messages that are empty and are t |