[Winpcap-users] filter string advice urgently needed
Pedro Infantilo
infantilo at hotmail.com
Thu Oct 8 07:28:42 PDT 2009
Hi and sorry for begging for help.
i've found no clue how to convert my wireshark-filter string to winpcap filter.
Here's what's my filter looks like:
(eth.src==00:0e:0c:76:86:5e)&&((frame.protocols=="eth:llc:netbios:data")||(frame.protocols=="eth:llc:netbios:dcerpc))
what i've currently managed is "eth src 00:0e:0c:76:86:5e" but i've no idea how to convert the other string.
Many thanks for any help/reply!!!
_________________________________________________________________
Windows Live: Friends get your Flickr, Yelp, and Digg updates when they e-mail you.
http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_3:092010
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.winpcap.org/pipermail/winpcap-users/attachments/20091008/3cbfdd0d/attachment.htm
More information about the Winpcap-users
mailing list