This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi,I have one socket chat program and I want capture their traffic, I want write a filter that can capture based on special text ,for example if they said "hi" ,wireshark capture it . please help me to write this filtering .

asked 26 Mar '16, 04:01

Eli's gravatar image

Eli
6112
accept rate: 0%

edited 20 Jul '16, 15:44

cmaynard's gravatar image

cmaynard ♦♦
9.3k1038142


In the unlikely case of your chat traffic being un-encrypted the filter would be

frame contains "hi" or frame contains "Hi"

but I have doubts that his is the case. If it is TLS encrypted you cannot see the plain text data and therefore cannot filter on the content of the encrypted packets.

Regards Matthias

permanent link

answered 26 Mar '16, 09:16

mrEEde's gravatar image

mrEEde
3.9k152270
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×349
×31

question asked: 26 Mar '16, 04:01

question was seen: 1,063 times

last updated: 20 Jul '16, 15:44

p​o​w​e​r​e​d by O​S​Q​A