Ask Your Question

salwa1215's profile - activity

2020-07-10 17:43:48 +0000 received badge  Commentator
2020-07-10 17:43:48 +0000 commented question Why am I not seeing any zero-length TCP segments in one capture file?

TCP segment len There are some packets with TCP segment len which is different to zero and other is equal to zero like

2020-07-10 16:56:43 +0000 asked a question Why am I not seeing any zero-length TCP segments in one capture file?

Dont get the NULL length payload from pcap Is there any reason to get the NULL length payload from a pcap file and dont

2020-07-06 09:50:47 +0000 answered a question detecting duplication and retransmission

Thanks for your response. Is TCP Dup ACK considered as a duplicated packets also ? and why I have the same ip.id fo

2020-07-06 09:04:17 +0000 asked a question TCP analysis

TCP analysis I need you help to confirm or not theses notions plz. I'm trying to extract some TCP.analysis fields using

2020-06-27 20:25:25 +0000 asked a question how to recognize a duplicate packet in wireshark ?

how to recognize a duplicate packet in wireshark ? how to recognize a duplicate packet ? in addition that it is marked i

2020-06-25 11:30:29 +0000 asked a question Handshake Modbus/TCP

Handshake Modbus/TCP I want to know how is the handshake of Modbus/TCP plz. I have a pcap file in which after each repon

2020-06-25 10:26:44 +0000 received badge  Rapid Responder
2020-06-25 10:26:44 +0000 answered a question How detecting a botnet from a pcap file ?

I dont apply for Android. I used it for linux machine. I tested tcp.port==5555 or tcp.port in {5555..5585} but they are

2020-06-25 10:24:42 +0000 asked a question detecting duplication and retransmission

detecting duplication and retransmission How can we distingush duplication from transmission tcp plz ? I undestand that

2020-06-24 15:14:37 +0000 asked a question How detecting a botnet from a pcap file ?

How detecting a botnet from a pcap file ? I want to know if there is a way to detect a botnet like Ares botnet from a pc

2020-06-16 10:16:45 +0000 asked a question How ip addess are read in wireshark ?

How ip addess are read in wireshark ? Are the ip source address and destination in wireshark the same as in as packet or

2020-06-16 10:15:23 +0000 asked a question How ip address are read in wireshark ?

How ip address are read in wireshark ? Are the ip source address and destination in wireshark the same as in as packet o

2020-05-14 12:32:30 +0000 commented question How can I get the flow count from a pcap file ?

flow is all packets belonging to this quintuplet (src ip, dest ip, src port, dest port, protocol)

2020-05-13 18:06:08 +0000 asked a question How can I get the flow count from a pcap file ?

How can I get the flow count from a pcap file ? I have a basic question please. I want to know how can get the flows cou

2020-05-02 18:48:35 +0000 received badge  Rapid Responder
2020-05-02 18:48:35 +0000 answered a question remove modbus packets/filter modbus

not tcp.port==502 does not work. It remove also all tcp packets

2020-05-02 00:51:59 +0000 commented question remove modbus packets/filter modbus

Oh i did think to that. Maybe it will work. I will test it tomorrow and give you a feedback. Thanks

2020-05-01 23:22:05 +0000 commented question remove modbus packets/filter modbus

The file is big but packets I dont know. My wireshark version is : 3.2.1

2020-05-01 22:45:09 +0000 commented question remove modbus packets/filter modbus

The packets that I want exclude are the modbus/tcp packets

2020-05-01 21:49:16 +0000 commented question remove modbus packets/filter modbus

File -> export specify packets and export eitheir dispayed packet or marked parckets (after doing ctrl shift m to mar

2020-05-01 17:24:25 +0000 asked a question remove modbus packets from my pcap file

remove modbus packets from my pcap file I want to remove the mobus packets from my pcap file and save the results in a f

2020-05-01 17:22:17 +0000 asked a question remove modbus packets/filter modbus

remove modbus packets/filter modbus I want to remove the mobus packets from my pcap file and save the results in a file.

2020-03-12 15:37:34 +0000 asked a question How can I capture an attack traffic ?

How can I capture an attack traffic ? I need the community opinion please. For my project, I have to perform some attac

2020-03-12 15:36:10 +0000 asked a question How can I capture a attack traffic ?

How can I capture a attack traffic ? I need the community opinion please. For my project, I have to perform some attack

2020-01-24 14:55:52 +0000 received badge  Rapid Responder
2020-01-24 14:55:52 +0000 answered a question how make a diff between two pcap files ?

Both files are captured in the same time but in two different machine. One machine makes port mirorring traffic and the

2020-01-24 14:17:49 +0000 asked a question how make a diff between two pcap files ?

how make a diff between two pcap files ? I have two pcap files and I want to make the difference between them. And store

2019-12-30 09:21:47 +0000 asked a question How doing the diff between two pcap file and store de results

How doing the diff between two pcap file and store de results I want to compare the difference between two pcap files an

2019-09-12 08:01:44 +0000 commented answer Display filter field names in the csv file

Thank you very much It works

2019-09-07 22:10:48 +0000 asked a question Display filter field names in the csv file

Display filter field names in the csv file Hello, I use this command to filter some field from my pcap file and store t

2019-06-12 09:12:05 +0000 commented answer Tshark commands lines statistics

Thanks so much grahamb

2019-06-09 23:44:33 +0000 asked a question Tshark commands lines statistics

Tshark commands lines statistics I want to know if there are some tshark commands lines which allow get these statistics

2019-06-09 23:42:45 +0000 asked a question tshark commands line statistics

tshark commands line statistics I want to know if there are some tshark commands lines which allow get these statistics