1. ip.addr == 10.0.0.1 [Sets a filter for any packet with 10.0.0.1, as either the source or dest]
2. ip.addr==10.0.0.1 && ip.addr==10.0.0.2 [sets a conversation filter between the two defined IP addresses]
3. http or dns [sets a filter to display all http and dns]
4. tcp.port==4000 [sets a filter for any TCP packet with 4000 as a source or dest port]
5. tcp.flags.reset==1 [displays all TCP resets]
6. http.request [displays all HTTP GET requests]
7. tcp contains traffic [displays all TCP packets that contain the word ‘traffic’. Excellent when searching on a specific string or user ID]
8. !(arp or icmp or dns) [masks out arp, icmp, dns, or whatever other protocols may be background noise. Allowing you to focus on the traffic of interest]
9. udp contains 33:27:58 [sets a filter for the HEX values of 0x33 0x27 0x58 at any offset]
10. tcp.analysis.retransmission [displays all retransmissions in the trace. Helps when tracking down slow application performance and packet loss]
http://www.lovemytool.com/blog/2010/04/top-10-wireshark-filters-by-chris-greer.html
'List > Windows' 카테고리의 다른 글
OAuth 2.0 Client 개발 (using Java, python) (0) | 2016.10.04 |
---|---|
binary diffing tool - bindiff (0) | 2016.02.14 |
Explain about KMPlayer bughunting (basic) (0) | 2016.02.14 |
Anti Debugging (0) | 2016.01.03 |
공유기 허브모드에서 관리자페이지 접속 방법 (0) | 2015.09.30 |