Question and Answer Collection

BPF Syntax

What does BPF stand for?

Berkeley Packet Filter


wlan.addr == c5:52:7e:95:6:8d && wlan.fc.type_subtype == 0x02. How many primitives are in this expression?

2


Apply a filter to display all packets on port 80 with the source IP of 10.0.50.227. What is the length of the second GET request?

385


Apply a filter to display all UDP packets on port 57190. What is the timestamp of the final packet?

11:54:43.808109


Apply a filter which reads all traffic apart from DNS and TCP, and output this to a file. What is the md5sum of this file?

b942d25b012745422c1710ac26419da6