• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 839
  • Last Modified:

wireshark, snort, how do you look for a bit pattern from a pcap file

$EXTERNAL_NET:any
$SQL_SERVERS:1433
msg:"ET EXPLOIT xp_fileexist access"
flow:to_server,established
content:"x|00|p|00|_|00|f|00|i|00|l|00|e|00|e|00|x|00|i|00|s|00|t|00|"

I have captured a pcap file.  How do I look for this data pattern using wireshark?
0
rgbcof
Asked:
rgbcof
  • 2
1 Solution
 
Galtar99Commented:
Click Edit|Find Packet
Click Hex value or String depending on what you're looking for
Put in your value in the Filter box, click Packet bytes and then find.
0
 
rgbcofAuthor Commented:
Very cool.  Which zone is best to ask for snort, wireshark type of questions?
0
 
Galtar99Commented:
I think the Networking|Protocols Zone would be the closest fit for it.
0

Featured Post

A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now