Hello, i want to extract the hex data from this SSL but when i type tshark -Vnr -r pcap -R (filter) > textfile i only get the details of the pcap without the hex part so i want to know if there is a way to extract the hex data with the details not the details only, i don't want to decrypt or anything i just want to extract it to a plain text, thanks.! asked 30 Sep '13, 04:35 Ziad Kiwan |
2 Answers:
Have you tried using the "-x" command line option? In your case:
answered 30 Sep '13, 13:42 SYN-bit ♦♦ sorry i'm not that good in wireshark and tshark what does vnxr do ? (30 Sep '13, 13:51) Ziad Kiwan I added the "-x" option to the options you already mentioned in your original question, as that option adds the output of the hex dump.
(30 Sep '13, 14:22) SYN-bit ♦♦ okay thanks for the information, that something good to learn! (01 Oct '13, 04:53) Ziad Kiwan |
O.K. please check these similar questions: see my (last) comment regarding disabling protocols to get the payload! also here
and here http://ask.wireshark.org/questions/16592/tcp-stream-output-in-pdml-format Regards answered 30 Sep '13, 07:16 Kurt Knochner ♦ edited 30 Sep '13, 07:17 can i apply a a filter in this and it will keep working ? i saw this before and tried it and the data stayed the same (30 Sep '13, 07:29) Ziad Kiwan
what do you mean? Which filter? (30 Sep '13, 07:55) Kurt Knochner ♦ its not working i'm not getting the ssl hex data out of the pcap using any of the methods you suggested, about the filter i use a filter to filter the pcap's and then i add them in a plain text (30 Sep '13, 13:37) Ziad Kiwan |
do you mean the decrypted payload?
when you open the pcap file using wireshark you see the detailed information and the hex information i want to retrieve them "all" using tshark is there a way ?
So, you need the 'raw' TCP payload, regardless of SSL decryption?
exactly! i want the raw data