Although Wireshark does not have a nice feature to export SMB2 objects, you can extract transferred files from the capture files.
In this article I will show you how to extract small files, a pdf and a exe, from Wireshark capture files.
PDF
The sample file smb2-pdf_02.pcap contains the file willhackforsushi.com_80211_Pocket_Reference_Guide.pdf from Will Hack For Sushi.
You can download the files here:
• sample capture file smb2-pdf_02.pcap
• pdf willhackforsushi.com_80211_Pocket_Reference_Guide.pdf
Open the file smb2-pdf_02.pcap.
To check if "Allow subdissector to reassemble TCP streams" is turned on, go to:
• right-click Transmission Control Protocol in the Packet Details pane
• Protocol Preferences
• "Allow subdissector to reassemble TCP streams"
Continue reading "Wireshark and SMB2: extract files – part 1 (by Joke Snelders)" »












Recent Comments