Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Learning Wireshark

From: Keith Roberts <keith@xxxxxxxxxxxx>
Date: Sat, 24 Dec 2011 14:41:41 +0000 (GMT)
Hi All.

Is it possible to use wireshark to reconstruct (file carving?) email messages and their MIME attachments send across a network card, and also things like multimedia downloaded via TCP/IP protocols please? If so, how do I go about doing this from within Wireshark?

I'm talking about using a pcap file for this - not a live capture.

Kind Regards,

Keith Roberts

-----------------------------------------------------------
Websites:
http://www.karsites.net
http://www.php-debuggers.net
http://www.raised-from-the-dead.org.uk

All email addresses are challenge-response protected with
TMDA [http://tmda.net]
-----------------------------------------------------------