21

I was looking around to do some stuff with wireshark and I stumbled across a forum question from a 2012 in which someone actually replied with the people from the future in mind.

God bless you shearn89 🫡
Youre a real one

And to those that reply "I found the solution thx" and don't post it: eat a dick

Comments
  • 2
    Here's the post:
    https://osqa-ask.wireshark.org/ques...

    In case you ever need to export stuff from a wireshark capture
    Also works with custom fields and columns, quite neat
  • 10
    yupp, I do that too. OPs tend to get upset for necroposting, but IDC - that single necropost might save someone from the struggle I had
  • 3
    Where does this whole necroposting thing even come from?

    I know it is a thing since ever, but i never understood, why replying to old stuff is bad. And it can't only be database performance related.
  • 1
    @thebiochemic I have no idea

    I feel like its just moderators being insanely butthurt
  • 5
    There is even a badge to earn for necroing at SO.
  • 0
    This is why project should not have a "discord only" Policy
  • 0
    @Linux what is that policy?
  • 1
  • 0
    Just a hint...

    JSON export format (see tshark manpage) might be easier.

    Though you have to be a tad careful to take an iterative approach in parsing depending on how much you stuffed into it.

    It comes in very handy if you want to build a siphon, as in filtering sth specific out of a tcp stream.

    You just filter the necessary JSON objects, create a newline delimited JSON file so you can easily append JSON object to a file without keeping stuff in memory and then you have at least one migraine less.

    Especially useful if you need multiple fields (-e).

    https://tshark.dev/capture/tshark/

    Capture filters / View filters are preferred of course, but anything raw like a packet stream / payload / etc. needs to be done manually.
  • 0
    @IntrusionCM I do know about the JSON, but I was trying to get 1.5 GB raw binary data out so I wanted as little overhead as possible

    I then converted the text file with the values printed in hex into a regular binary like the answer mentions
  • 2
    I've done that so many times on Stackoverflow just because of the amount of time I ran into these stupid motherfuckers not writing their solution.

    The highest upvote count I got from answering my own question is about 80. I saved plenty of lives 😭
Add Comment