Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Re Hex Stream Decode (SCCP)

From: "Abhik Sarkar" <sarkar.abhik@xxxxxxxxx>
Date: Wed, 23 Jul 2008 15:19:16 +0400
Hi Hoosain,

I am glad it worked for you. With a DLT of 141, I am sure tshark
should be able to read the file and display the decoded protocol tree
with
tshark -r pdu.cap -V
This works on my Windows PC and I am sure it will on Linux too.

(hope I understood your requirement correctly).
Abhik.


On Wed, Jul 23, 2008 at 11:42 AM, Hoosain Madhi <madhih@xxxxxxxxxxxxx> wrote:
> Hi Abhik
>
> Brilliant. Thank you for the guidance.
>
> I have made the following changes :
>
> text2pcap -l 141 pdu.txt pdu.cap
> (ie. bpf.h : #define DLT_MTP2        141)
>
> and get the following decode
>
> --------------------------------------------------------------------------------------------------------------------------
> No.     Time                       Source
> Destination           Protocol Info
>       1 2008-07-23 09:38:26.000000 8712
> 8744                  GSM MAP  returnResultLast sendRoutingInfoForSM
>
> Frame 1 (128 bytes on wire, 128 bytes captured)
> Message Transfer Part Level 3
> Signalling Connection Control Part
> Transaction Capabilities Application Part
> GSM Mobile Application
>
> 0000  83 28 22 82 d8 09 01 03 0e 19 0b 12 08 00 11 04   .(".............
> 0010  43 26 92 69 11 01 0b 12 06 00 11 04 72 28 19 10   C&.i........r(..
> 0020  63 06 5d 64 5b 49 04 5b ba 83 0a 6b 2a 28 28 06   c.]d[I.[...k*((.
> 0030  07 00 11 86 05 01 01 01 a0 1d 61 1b 80 02 07 80   ..........a.....
> 0040  a1 09 06 07 04 00 00 01 00 14 03 a2 03 02 01 00   ................
> 0050  a3 05 a1 03 02 01 00 6c 27 a2 25 02 01 01 30 20   .......l'.%...0
> 0060  02 01 2d 30 1b 04 08 56 05 81 23 00 20 25 f9 a0   ..-0...V..#. %..
> 0070  0f 81 07 91 72 28 19 40 40 f7 04 04 00 01 a1 15   ....r(.@@.......
> --------------------------------------------------------------------------------------------------------------------------
>
> The next step is to use tshark to do the decoding on the command line. Any
> ideas please for Linux.
>
>
> Much appreciated.
>
> Regards
>
> ---------
> Hoosain Madhi
> Network Quality - Service Assurance
> Group Mobile Engineering
> Vodacom