YOHO
YOHO

Reputation: 77

How to ensure a .pcap file did not modified?

let say my friend send me a .pcap file capture by his computer Wireshark, and I know there had some software can modify this pcap file.(Such as EditCap)

How can I ensure the file had not modify by those software? (I would like to ensure the pcap file must be original create by Wireshark)

Thank you

Upvotes: 1

Views: 146

Answers (1)

Evan
Evan

Reputation: 6545

You can't. The pcap format has no built-in verification or validation that cannot be trivially spoofed.

Upvotes: 2

Related Questions