wireshark, snort, how do you look for a bit pattern from a pcap file

msg:"ET EXPLOIT xp_fileexist access"

I have captured a pcap file.  How do I look for this data pattern using wireshark?
Who is Participating?
Galtar99Connect With a Mentor Commented:
Click Edit|Find Packet
Click Hex value or String depending on what you're looking for
Put in your value in the Filter box, click Packet bytes and then find.
rgbcofAuthor Commented:
Very cool.  Which zone is best to ask for snort, wireshark type of questions?
I think the Networking|Protocols Zone would be the closest fit for it.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.