Good Day All,
Can someone possibly help me. I am trying to come up with a display filter,
but have been unsuccessful.
I am trying to filter on the Message section of a smtp packet.
Here is what I see
Frame
Ethernet
IP
TCP
SMTP ----\/
Message: Received: from machine.hostname.com
I am trying to wrote a couple of different filters for "Recieved: from" but
it don't return the correct results.
I have tried tcp[42:1]=52 trying to find the "R" that didn't work
smtp contains "Recieved:" didn't work
Any Idea's??
Powered by MHonArc 2.6.10