Wireshark-users: Re: [Wireshark-users] Extracting files from pcap
From: "Abhik Sarkar" <sarkar.abhik@xxxxxxxxx>
Date: Sun, 12 Oct 2008 09:53:56 +0400
If the file is transferred using HTTP, you could try File > Export >
Objects > HTTP.

On Sun, Oct 12, 2008 at 8:57 AM, Jim Balo <jimbalo22@xxxxxxxxx> wrote:
> Hi,
>
> I am trying to learn how to extract transferred files from pcap dumps.
>
> I have a pcap file with an http data transfer that is gzip-encoded
> ("Accept-encoding: gzip,deflate" in the http header).  I tried selecting and
> exporting the data portion of the two packages that seemed to be part of
> this transfer and then concatenate them, but when I try to gunzip it, I get
> "unexpected end of file."  Using Network Miner, the file decodes just fine.
>
> I would like to learn how to do this using only Wireshark - does anyone know
> of a good guide on how to do this in Wireshark?
>
> Thanks,
> JB
>
>
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> https://wireshark.org/mailman/listinfo/wireshark-users
>
>