Using TShark, I want to be able to extract the payload in HTTP response from packets data captured through tshark in a .pcap file.
In the Wireshark GUI, I was able to do that by
The question is that how can I do it in Tshark?
asked 19 Aug '16, 03:16
In short, not implemented yet :(
EDIT: As of Wireshark 2.3.0, this feature is available. As of December 2016, Wireshark 2.3.0 hasn't been released yet, so you can grab a daily build from here. To extract HTTP objects from the command-line, run the following command:
answered 13 Nov '16, 09:29
edited 13 Dec '16, 15:30