Question : wireshark, snort,  how do you look for a bit pattern from a pcap file

$EXTERNAL_NET:any
$SQL_SERVERS:1433
msg:"ET EXPLOIT xp_fileexist access"
flow:to_server,established
content:"x|00|p|00|_|00|f|00|i|00|l|00|e|00|e|00|x|00|i|00|s|00|t|00|"

I have captured a pcap file.  How do I look for this data pattern using wireshark?

Answer : wireshark, snort,  how do you look for a bit pattern from a pcap file

Click Edit|Find Packet

Click Hex value or String depending on what you're looking for

Put in your value in the Filter box, click Packet bytes and then find.

Random Solutions  
 
programming4us programming4us