The use of filter for wireshark
Wireshark has two types of filters.
Capture filter
Display filter
Capture filter-Capture---- > Options---- > Capture Filter.
BPF qualifier (Berkeley Packet Filter)
Examples: host, net, port, src, dst, ether, ip, tcp, udp, http, ftp.
Operator: & & | |!
For example: dst host 200.0.0.1 & & tcp port 80
Port http but cannot be http.
Icmp [0] = = 8 indicates that the bit value with a packet offset of 0 is 8.
Icmp [0:2] = = 0x0301 indicates that the packet offset is 0 and continues two bytes, with a value of 0x0301.
Icmp packet format:
0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 9 0 1 2 3 4 5 6 7 8 9 0 1 + -+ | Type | Code | Checksum | +-+ | unused | | +-+ | Internet Header + 64 bits of Original Data Datagram | +- For more information, see http://www.ietf.org/rfc/rfc792.txtTCP Header Format 0 1 2 3 0 1 2 3 4 5. 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 7 8 9 0 1 +-+ | Source Port | Destination Port | +-+-+ -+ | Sequence Number | +-+- +-+ | Acknowledgment Number | +- +-+ | Data | | U | A | P | R | S | F | | Offset | Reserved | R | C | S | Y | I | Window | G | K | H | T | N | N | +-- +-+ | Checksum | Urgent Pointer | +-+ | Options | Padding | +-+ | data | +-+- For more information on +-+ TCP Header Format, see: http://www.ietf.org/rfc/rfc793.txt only captures packets marked as RST by tcp? Tcp [13] & 4 blocks 4, packet bit offset 13 bytes, what does "& 4" mean? Because RST represents the number 4 in this 13th byte [* (128) * (64) urg (32) ack (16) psh (8) rst (4) syn (2) fin (0)]. What about syn+ack? Tcp [13] = = 18. Display filter
Click expression to specify a detailed expression. Here are some common ones: ip.addr==192.168.1.1frame.len