Solved

WireShark (Win32) - Possible to search for ascii string in packets?

Posted on 2008-10-05
4
4,003 Views
Last Modified: 2012-05-05
I have a large collection of packets i've been sniffing... the issue is there is a lot of data from various connections, etc.

I wanted to find out if it was possible to search the actual packet collection data for packets that match a specific ascii string using the filter

for example filter tcp.port eq 80 would show only packets that were sent/received on port 80... i want to show only packets that contain a specific ascii (or hex) string

0
Comment
Question by:mcainc
  • 3
4 Comments
 
LVL 31

Expert Comment

by:moorhouselondon
Comment Utility
I would say that it is better to setup  a filter without this criteria, but when you have saved the log somewhere, then look for strings.  The reason being that the string may be split between different packets, so if you were searching for "hello world", "hello" might be in one packet "world" would be in another - packets don't treat spaces as delimiters, so it could be "hell" in one packet "o world" in another.  
0
 

Author Comment

by:mcainc
Comment Utility
the particular project i'm working on has very small packets, nothing is broken up... is this possible in the actual win32 gui or would i have to parse the .pcap file?
0
 
LVL 31

Expert Comment

by:moorhouselondon
Comment Utility
I setup a filter using the TCP only filter, then started capture.  I then logged into my webmail app, stopped Wireshark capturing.  In the displayed capture log, I went into Edit, Find, selected the string radio button, and searched for my password, which it found in the log.

If you wanted to capture only packets meeting the search criteria then you would have to define a custom capture filter - is this what you are trying to do?  
0
 
LVL 31

Accepted Solution

by:
moorhouselondon earned 500 total points
Comment Utility
There are examples here to capture only packets containing certain text strings

http://wiki.wireshark.org/DisplayFilters
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Large and small networks have one same need, Service monitoring. Service monitoring consists of watch services of the several servers in the network. To monitor means that the administrator will receive an alert when a service is down or it's state …
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now