This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Can someone tell me how to look at a packet in raw form. I want to see the preamble and every octet after in binary or hex form. I want to look at the packet and find the destination ip adress,the payload length, the payload, etc.

For example I will go to google.com in my browser and then look at the raw response.

asked 14 Aug '12, 13:41

guitardenver's gravatar image

guitardenver
1111
accept rate: 0%


Wireshark will not show you the Ethernet preamble or the start-of-frame delimiter; they are not present in the frame when Wireshark sees it. Ethernet frames will start with the destination MAC address.

To see everything in hex, simply make sure the Packet Bytes pane is visible (View > Packet Bytes). The packet contents will be shown on the left in hex, and on the right in ASCII.

permanent link

answered 14 Aug '12, 14:53

Jim%20Aragon's gravatar image

Jim Aragon
7.2k733118
accept rate: 24%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×293
×248
×23
×20

question asked: 14 Aug '12, 13:41

question was seen: 4,782 times

last updated: 14 Aug '12, 14:53

p​o​w​e​r​e​d by O​S​Q​A