Skip to content

Instantly share code, notes, and snippets.

@jborean93
Created September 21, 2021 20:18
Show Gist options
  • Save jborean93/664d1a6d94fecab889b5ff9b5a0017a9 to your computer and use it in GitHub Desktop.
Save jborean93/664d1a6d94fecab889b5ff9b5a0017a9 to your computer and use it in GitHub Desktop.
Dissects raw bytes in Wireshark - TLS example
DATA='FgMDAK0BAACpAwNhSjqVL8AO4n3tp9BCagd/Vo9FoZNVsPCXppc9JBVR5AAAKsAswCvAMMAvAJ8AnsAkwCPAKMAnwArACcAUwBMAnQCcAD0APAA1AC8ACgEAAFYAAAAVABMAABBkYzAxLnNwbmVnby50ZXN0AAoACAAGAB0AFwAYAAsAAgEAAA0AGgAYCAQIBQgGBAEFAQIBBAMFAwIDAgIGAQYDACMAAAAXAAD/AQABAA=='
echo $DATA | base64 -d | hexdump -C | text2pcap -T 8443,443 - /tmp/tls1.pcap
DATA='FgMDAxkCAABRAwNhSjqVHJjKhHmYNy8Aniontsb2E5QYxbz2QsA3F9eNeiDSOgAAQEsXpIvV6wzFIsyXlm71Eev27j0vgm4dGVXGKcAwAAAJABcAAP8BAAEACwABzwABzAAByTCCAcUwggEuoAMCAQICEBqN+uO8ErCUQ+TCAAb14K0wDQYJKoZIhvcNAQEFBQAwITEfMB0GA1UEAxMWV1NNQU4tREMwMS5zcG5lZ28udGVzdDAeFw0yMTA5MjExOTU1MzVaFw0yMjAzMjAxOTU1MzVaMCExHzAdBgNVBAMTFldTTUFOLURDMDEuc3BuZWdvLnRlc3QwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANhKH7CEIsLA5/qs444gW7NSsAoFMIwKLAfYRpgX+lzdh8dWWojGG8ucZE6jiepRfODvOCbonSVI9vdtdNM+NHdZwDRuBTemCGrw/JXiqXzZwy+Ky5yBb9JpEc9llyK9YsamUvO04yA54uhYJpQxxiAggXNcUHq3NVJeQX1K3KItAgMBAAEwDQYJKoZIhvcNAQEFBQADgYEAsA40izL+mUun6C8U8Hwu/mR/1+/ZGvLaQ+MUWNfNU9ClX5Sw+EniWDjU1fPclPAY8YSOE6fbj5PhbdK8leydy2Q4tceYzWgi0mlK9cZVpplx86zKAM/1tC1OnmvudFy+9w9M36+UeBpw/0ZHBi4kJAIREWzoOo9wP+0UTX1ZF6gMAADpAwAYYQRhWiDICTtqAlwvwPth83JBuUEC3RgTUdMH09FPgP0Ipo5GPLJ11BLicn38+2dmsMVfC+CTvF6qQqUtuvRbuuSih/r9cKb6U0Q4DNII5w6cmr+VAkzh2JL85JO1YB2KoqAIBACAoq29Dt6vOHwF1JOi/MCxwvpkcWd0smqsQW+jVymNv/LrPfNEn/y7Rd0OqwHsiMSUtafGXN+OZURP3JQ9gCTmb8PG0D3QEpoc4RmuGNQ2u4tjVHuSAhC8D7J/pckN3Okb+v305Zu9A68h6qAj4ZL5WVUakg8GdAPMeI9B5lV27GoOAAAA'
echo $DATA | base64 -d | hexdump -C | text2pcap -T 443,8443 - /tmp/tls2.pcap
mergecap -a /tmp/tls1.pcap /tmp/tls2.pcap -w /tmp/tls.pcap
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment