Wireshark-users: Re: [Wireshark-users] text2pcap - strange packets after converting a Hex-dump

From: Shain Singh <shain.singh@xxxxxxxxx>
Date: Thu, 23 Jun 2011 11:53:27 +1000
Hi Robert,

Writing to file: “tshark  -i eth1 –n port 443 –V –R http | grep -e "^[0-9a-f][0-9a-f][0-9a-f][0-9a-f]" > file_hex.dump”


The file you are writing to is just an ASCII representation of the output and not a PCAP file. I tried this command and my output file is just text and not hex.

Have you tried using the -w option to output the file as a PCAP file?



--
Shaineel Singh
e: shain.singh@xxxxxxxxx
p: +61 422 921 951
w: http://buffet.shainsingh.com

--
"Too many have dispensed with generosity to practice charity" - Albert Camus