This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I am trying to create a capture filter for a DNS request. I can match the hex but specific payload pattern changes places.

udp[18:4]=0x* or udp[19:4]=0x* or udp[20:4]=0x**

can I match specific payload at several packet/locations using a easier capture expression? perhaps rex?

Can anyone help me please ?

Thanks you.

asked 23 Jan '17, 08:07

Oskarino's gravatar image

Oskarino
6112
accept rate: 0%

1

There was a gorgeous talk (https://youtu.be/DS4j9pwVuog) by Sake at Sharkfest explaining BPF (capture filter) in detail. The presentation is also available (https://sharkfest.wireshark.org/assets/presentations16/13.pdf).

Maybe this helps.

(24 Jan '17, 02:28) Uli
Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×184
×10

question asked: 23 Jan '17, 08:07

question was seen: 556 times

last updated: 24 Jan '17, 02:28

p​o​w​e​r​e​d by O​S​Q​A