On Tue, May 15, 2007 at 10:11:09PM +0000, Stefan Puiu wrote:
> If I try to export a capture, I get packet bytes in hex and the text
> on the right hand side, with very short lines, so it's not useful -
> this is probably because the message is part SOCKS, part text. Is it
> possible to somehow have wireshark decode or export a certain field as
> ASCII? Something along the lines of "show raw SIP message" for SIP,
> but only for a field in SOCKS messages.
Have you tried the Follow TCP Stream feature in the Analyze menu?
Steve