Wireshark mailing list archives
Display filter for TCP reserved field
From: Marco Simone Zuppone <msz () msz eu>
Date: Wed, 29 Sep 2010 17:17:50 +0100
Hello, I was wondering how is the best way (if any) to create a filter about the reserved ( 4 bits between bit 100 and 104 ) field of the TCP packet. The expression as tcp[n:y] == are interesting but n and y are expressed in byte and not in bit. My idea was to create a filter to spot strange packet: thil 4 bit filed should be 0000 but I was wandering if some strange application is filling it with data... Do you know some ways ?? Thanks in advance. Marco S. Zuppone
___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- Display filter for TCP reserved field Marco Simone Zuppone (Sep 29)
- Re: Display filter for TCP reserved field Stephen Fisher (Sep 29)
- Re: Display filter for TCP reserved field Marco S . Zuppone (Sep 29)
- Re: Display filter for TCP reserved field Stephen Fisher (Sep 29)
- Re: Display filter for TCP reserved field Marco S . Zuppone (Sep 29)
- Re: Display filter for TCP reserved field Stephen Fisher (Sep 29)