Wireshark mailing list archives

Searching for Hex in a pcap file using tshark


From: Wes <wes_r () yahoo com>
Date: Wed, 5 Oct 2011 12:00:47 -0700 (PDT)

Is there an equivalently method of doing an Edit->Find Packet->Hex value in Wireshark with command options in tshark?

I have a packet capture file and I just want to search for 6 hex digits such as a Mac address in order to confirm or 
deny if it's present. Dumping the text and grepping doesn't always work due to line wraps.

I've tried multiple -R filters, but haven't hit on the right one yet...

Thanks,

Wes
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: