Solved

WireShark (Win32) - Possible to search for ascii string in packets?

Posted on 2008-10-05
4
4,009 Views
Last Modified: 2012-05-05
I have a large collection of packets i've been sniffing... the issue is there is a lot of data from various connections, etc.

I wanted to find out if it was possible to search the actual packet collection data for packets that match a specific ascii string using the filter

for example filter tcp.port eq 80 would show only packets that were sent/received on port 80... i want to show only packets that contain a specific ascii (or hex) string

0
Comment
Question by:mcainc
  • 3
4 Comments
 
LVL 31

Expert Comment

by:moorhouselondon
ID: 22644380
I would say that it is better to setup  a filter without this criteria, but when you have saved the log somewhere, then look for strings.  The reason being that the string may be split between different packets, so if you were searching for "hello world", "hello" might be in one packet "world" would be in another - packets don't treat spaces as delimiters, so it could be "hell" in one packet "o world" in another.  
0
 

Author Comment

by:mcainc
ID: 22644496
the particular project i'm working on has very small packets, nothing is broken up... is this possible in the actual win32 gui or would i have to parse the .pcap file?
0
 
LVL 31

Expert Comment

by:moorhouselondon
ID: 22644686
I setup a filter using the TCP only filter, then started capture.  I then logged into my webmail app, stopped Wireshark capturing.  In the displayed capture log, I went into Edit, Find, selected the string radio button, and searched for my password, which it found in the log.

If you wanted to capture only packets meeting the search criteria then you would have to define a custom capture filter - is this what you are trying to do?  
0
 
LVL 31

Accepted Solution

by:
moorhouselondon earned 500 total points
ID: 22644818
There are examples here to capture only packets containing certain text strings

http://wiki.wireshark.org/DisplayFilters
0

Featured Post

Save on storage to protect fatherhood memories

You're the dad who has everything. This Father's Day, make sure your family memories are protected. My Passport Ultra has automatic backup and password protection to keep your cherished photos and videos safe. With up to 3TB, you have plenty of room to hold the adventures ahead.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Ping Sniffer 14 49
CDC audit 17 101
Speed testing 26 96
Sonicwall Firewall -- automatic nightly 2am speed tests ? 1 61
Many network operators, engineers, and administrators do not take several factors into consideration when troubleshooting network throughput and latency issues.  They often  measure the throughput by performing a measurement  by transferring a large…
Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now