Wireshark-users: Re: [Wireshark-users] packet payload string or hex filter
From: Stephen Fisher <stephentfisher@xxxxxxxxx>
Date: Fri, 22 Feb 2008 10:48:50 -0700
On Fri, Feb 22, 2008 at 01:49:29AM -0800, Guy Harris wrote:
> Sake Blok wrote:
> > On Thu, Feb 21, 2008 at 10:01:48PM -0700, Stephen Fisher wrote:
> 
> 	...
> 
> >> This is not currently possible because there is no field that contains 
> >> the contents of the entire frame.
> 
> Actually, there is - "frame".

> And
> 	frame contains "blablabla"
> or
> 	frame contains 00:40:3f

Thanks for the correction.  I tried it last night and I thought it 
wasn't working when I typed frame contains, but this morning it does 
indeed work. :O


Steve