Packet sniffer: Difference between revisions

From LemonWiki共筆
Jump to navigation Jump to search
(Created page with "== case: try to find mp4 file == keyword filter at URL Snooper v.2.30.01 * full request URI: ex: {{kbd | key=<nowiki>http://www.example.com/folder/file.mp4</nowiki>}} ok * partia...")
 
mNo edit summary
Line 6: Line 6:


Filter at Wireshark 1.6.5
Filter at Wireshark 1.6.5
* full request URI: ex: {{kbd | key=ip.dst == 127.0.0.1 and http.request.uri matches "upload2/letsgo.mp4" }} (www.example.com was mapping to IP: 127.0.0.1) ok
* full request URI: ex: {{kbd | key=ip.dst == 127.0.0.1 and http.request.uri matches "upload2/letsgo.mp4" }} (where the domain www.example.com was mapping to IP: 127.0.0.1) ok
* partial URI path: ex: {{kbd | key=http.request.uri matches "/folder/file.mp4"}}, {{kbd | key=http.request.uri matches "file.mp4"}}, {{kbd | key=http.request.uri matches "mp4"}} ok
* partial URI path: ex: {{kbd | key=http.request.uri matches "/folder/file.mp4"}}, {{kbd | key=http.request.uri matches "file.mp4"}}, {{kbd | key=http.request.uri matches "mp4"}} ok
* wildcat: ex: {{kbd | key=http.request.uri matches "*.mp4" }} not work {{exclaim}}
* wildcat: ex: {{kbd | key=http.request.uri matches "*.mp4" }} not work {{exclaim}}

Revision as of 14:57, 2 February 2012

case: try to find mp4 file

keyword filter at URL Snooper v.2.30.01

  • full request URI: ex: http://www.example.com/folder/file.mp4 ok
  • partial URI path: ex: /folder/file.mp4, file.mp4, mp4 ok
  • wildcat: ex: *.mp4 not work Icon_exclaim.gif

Filter at Wireshark 1.6.5

  • full request URI: ex: ip.dst == 127.0.0.1 and http.request.uri matches "upload2/letsgo.mp4" (where the domain www.example.com was mapping to IP: 127.0.0.1) ok
  • partial URI path: ex: http.request.uri matches "/folder/file.mp4", http.request.uri matches "file.mp4", http.request.uri matches "mp4" ok
  • wildcat: ex: http.request.uri matches "*.mp4" not work Icon_exclaim.gif

software list

URL Snooper v.2.30.01

  • live sniffer: ok
  • save as file: n/a
  • time stamp: n/a

Wireshark 1.6.5

  • live sniffer: ok
  • save as file: ok
  • time stamp: ok


reference