wireshark, snort, how do you look for a bit pattern from a pcap file

$EXTERNAL_NET:any
$SQL_SERVERS:1433
msg:"ET EXPLOIT xp_fileexist access"
flow:to_server,established
content:"x|00|p|00|_|00|f|00|i|00|l|00|e|00|e|00|x|00|i|00|s|00|t|00|"

I have captured a pcap file.  How do I look for this data pattern using wireshark?
rgbcofAsked:
Who is Participating?
 
Galtar99Connect With a Mentor Commented:
Click Edit|Find Packet
Click Hex value or String depending on what you're looking for
Put in your value in the Filter box, click Packet bytes and then find.
0
 
rgbcofAuthor Commented:
Very cool.  Which zone is best to ask for snort, wireshark type of questions?
0
 
Galtar99Commented:
I think the Networking|Protocols Zone would be the closest fit for it.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.