Wireshark mailing list archives
Using tshark to extract ssl.handshake.random_time in hex
From: Thomas Glanzmann <thomas () glanzmann de>
Date: Wed, 3 Aug 2016 00:35:18 +0200
Hello, I would like to use wireshark to extract the 4 bytes that represent ssl.handshake.random_time in hex. Currently I only managed to extract it as unix time by doing that: $ tshark -nr sniff.pcap -Y 'ssl.handshake.type == 1' -T fields -e ssl.handshake.random_time Aug 2, 2016 17:00:11.000000000 CEST Any hints how to obtain that? I'm using tshark 1.12.1 which is packaged with Debian jessie. In backports also 2.0.4 is available. But I'm also fine to compile wireshark by myself. Cheers, Thomas ___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: https://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- Using tshark to extract ssl.handshake.random_time in hex Thomas Glanzmann (Aug 02)