This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I'm trying to replace a specific MAC address in a pcap using tcp-rewrite and can't figure out how to do it. It looks like it replace ALL the macs when I use the -enet-dmac command (or -enet-smac). I want to substitute one specific MAC with another specific MAC.

asked 12 Sep, 00:07

kdani's gravatar image

kdani
26559
accept rate: 0%

Arguably, questions about tcprewrite are off topic for this site although there are a number of folks around that can help or suggest alternative approaches so I'll let these slide for now.

(12 Sep, 04:37) grahamb ♦

If you don't have the requirement of using tcprewrite it may be easier to do that with TraceWrangler. It requires Windows or running it using WINE on Linux.

permanent link

answered 12 Sep, 01:11

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

thanks, it is possible solution - I managed to do it using another tool: http://www.lovemytool.com/blog/2011/05/bittwiste-pcap-capture-file-editor-by-joke-snelders.html

(12 Sep, 05:09) kdani
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×5

question asked: 12 Sep, 00:07

question was seen: 315 times

last updated: 12 Sep, 05:09

p​o​w​e​r​e​d by O​S​Q​A