Wireshark

Gunters' site

Quod non est in actis non est in mundo


WireShark

ip.addr == 10.0.0.1

tcp or dns

tcp.port == 443

tcp.analysis.flags

!(arp or icmp or dns)

follow tcp stream

tcp contains facebook

http.response.code == 200

http.request

tcp.flags.syn == 1