Advertise on warmetal.nl!
Click for more information
about advertising here.

Did you find this website useful? Did I save you a lot of time?
Please consider donating to support this site:

 

Notes, Tips & Tricks: WireShark

This is a notes page, extended with tips & tricks. This page is not really documentation, just stuff for me to remember. Sometimes things will get removed from these pages and turned into real documentation, sometimes not. You might find these notes to come in hand, maybe not. For me, it's just things I don't want to forget.

Trace in linux:

tcpdump -w /tmp/tracefile

Je kan de trace beƫindigen met <ctrl> + c, waarna je de file kunt openen met wireshark.

Display filters

  • Only IP-address 10.10.10.10
    • ip.addr == 10.10.10.10
  • Everything except IP-address 10.10.10.10
    • !(ip.addr == 10.10.10.10)
  • Everything except DNS and NTP
    • !(udp.port == 53) and !(udp.port == 123)

Discussion

Enter your comment:
 
wiresharknotes.txt · Last modified: 2010/10/09 12:31 by sjoerd