Hi Alex,
You could try a display filter like this:
tcp[offset_within_tcp:num_bytes]==4e:10
More examples in:
http://wiki.wireshark.org/DisplayFilters
HTH
Abhik.
On Fri, Aug 8, 2008 at 9:02 PM, Alex Lee <Alex.Lee@xxxxxxxxxxxx> wrote:
> Can Wireshark perform byte offset matches like tcpdump does? For example, if
> I'm looking for something in the tcp options field, in tcpdump, to match
> against a hex value in that port of the tcp field, I'd do something like
> this:
>
>
>
> # tcpdump …………. tcp[33:2]=0x4e10
>
>
>
> If the captures are already taken in the WS cap format, is there a way I can
> use the expression above? It seems like this isn't the case but I thought
> I'd ask.
>
> Alex Lee
>
>
>
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> https://wireshark.org/mailman/listinfo/wireshark-users
>
>