I have a requirement of converting a hexdump of several packets into format which wireshark can understand. I have downloaded a pcap file online, opened it with wireshark and saved it as .txt file. This .txt file can be again opened by wireshark for analyzing.
If I can convert my hexdump into format present in .txt file then I can analyze it packet by packet. My question here is, what is the difference between pcap format and .txt format. Do I need to convert my hexdump compalsary into pcap format for analyzing ?
asked 18 Jan '16, 22:07
edited 18 Jan '16, 22:58
The pcap format you are referring to is a binary format for the collection of raw packet data and related meta data. The text format you are referring to is an (ASCII) text interpretation of the packet data and related meta data.
answered 19 Jan '16, 01:12