[Winpcap-users] filter string advice urgently needed

Pedro Infantilo infantilo at hotmail.com
Thu Oct 8 07:28:42 PDT 2009


Hi and sorry for begging for help.

i've found no clue how to convert my wireshark-filter string to winpcap filter.

Here's what's my filter looks like:

 

(eth.src==00:0e:0c:76:86:5e)&&((frame.protocols=="eth:llc:netbios:data")||(frame.protocols=="eth:llc:netbios:dcerpc))

 

 

what i've currently managed is "eth src 00:0e:0c:76:86:5e" but i've no idea how to convert the other string.

 

Many thanks for any help/reply!!!
 		 	   		  
_________________________________________________________________
Windows Live: Friends get your Flickr, Yelp, and Digg updates when they e-mail you.
http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_3:092010
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.winpcap.org/pipermail/winpcap-users/attachments/20091008/3cbfdd0d/attachment.htm 


More information about the Winpcap-users mailing list