This is our old Q&A Site. Please post any new questions and answers at

I am trying to create a capture filter for a DNS request. I can match the hex but specific payload pattern changes places.

udp[18:4]=0x* or udp[19:4]=0x* or udp[20:4]=0x**

can I match specific payload at several packet/locations using a easier capture expression? perhaps rex?

Can anyone help me please ?

Thanks you.

asked 23 Jan '17, 08:07

Oskarino's gravatar image

accept rate: 0%


There was a gorgeous talk ( by Sake at Sharkfest explaining BPF (capture filter) in detail. The presentation is also available (

Maybe this helps.

(24 Jan '17, 02:28) Uli
Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 23 Jan '17, 08:07

question was seen: 669 times

last updated: 24 Jan '17, 02:28

p​o​w​e​r​e​d by O​S​Q​A