如何从Wireshark复制捕获的数据包的十六进制数据 [英] How to copy hex data of captured packet form wireshark

查看:4116
本文介绍了如何从Wireshark复制捕获的数据包的十六进制数据的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

这是示例 这是捕获的数据包数据

here is the example this is the captured packet data

00000000  00 6e 0b 00                                                                          .n..
00000004  4d 5a e8 00 00 00 00 5b  52 45 55 89 e5 81 c3 81                    MZ.....[ REU.....
00000014  12 00 00 ff d3 89 c3 57  68 04 00 00 00 50 ff d0                       .......W h....P..
00000024  68 f0 b5 a2 56 68 05 00  00 00 50 ff d3 00 00 00                      h...Vh.. ..P.....
00000034  00 00 00 00 00 00 00 00  00 00 00 00 e0 00 00 00                    ........ ........
00000044  0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68                      ........ !..L.!Th
00000054  69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f                      is progr am canno
00000064  74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20                     t be run  in DOS 
00000074  6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00                     mode.... $.......

我只想要这样的十六进制部分

and i want only the hex part like this

  00 6e 0b 00 
  4d 5a e8 00 00 00 00 5b  52 45 55 89 e5 81 c3 81
  12 00 00 ff d3 89 c3 57  68 04 00 00 00 50 ff d0

我尝试右键单击数据包,然后选择复制->字节->十六进制流 但是我得到的十六进制数据根本不像上面的数据 所以我该如何从Wireshark复制捕获的数据包的十六进制数据?

I try right click on the packet and select copy -> bytes ->hex stream but the hex data I got doesn't look like the above data at all so How Can I copy hex data of captured packet form wireshark ?

感谢阅读

推荐答案

在Wireshark数据包列表"面板上,右键单击所需的数据包,然后:

On the Wireshark "packet list" panel, right click the packet you want and:

1)如果选择 Copy-> Bytes-> Hex stream ,您将获得十六进制数字作为一个没有空格的长字符串

1) if you select Copy->Bytes->Hex stream, you'll get the hex digits as one long string without white spaces

 39cb08004528053f000000006f1105faac11745dac11740c039......

2)如果选择 Copy-> Bytes-> Offset Hex ,您将获得GUI上显示的十六进制数字,包括每行起始字节的偏移(帧偏移)

2) if you select Copy->Bytes->Offset Hex, you'll get the hex digits as displayed on the GUI , including the offset of each line starting byte (frame offset)

0010   05 3f 00 00 00 00 6f 11 05 fa ac 11 74 5d ac 11    
0020   74 0c 03 9e 03 9d 05 2b 00 00 07 e0 8f ee 8f 1c    
0030   ff 00 00 00 00 00 09 0f 00 58 39 cb 60 00 00 00    
0040   11 80 08 00 73 00 02 44 00 00 00 00 03 dd de de

这篇关于如何从Wireshark复制捕获的数据包的十六进制数据的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆