Important display filters
In this section, we will look at some display filters which will come handy in day-to-day protocol analysis with regard to security.
Filters based on protocols
In this section, we will look at some of the most useful display filters for the more common protocols.
DNS
The commonly used display filters for DNS are as follows:
dns dns.query.response == 0 dns.query.response == 1 dns.flags.rcode == 2 [Server Failure]
FTP
Some of the common display filters that can be used while traversing FTP communication are as follows:
ftp.request.command == "USER"
: This filter is used to filter data based on a specific FTP command. A list of FTP commands can be found at http://en.wikipedia.org/wiki/List_of_FTP_commands.ftp.request.arg == "anonymous" ...
Get Wireshark Network Security now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.