Viewing TCP/IP payload in Wireshark

When using the network protocol analyzer Wireshark, if you’re specifically looking for the payload, look for the [PSH, ACK] tag in the “Info” column.  Once you click on the row with that tag, you will see the “Data” node in the packet window as shown in the attached window.

Wireshark TCP data

Wireshark TCP data

The other tags ([ACK], [SYN], [FIN,ACK]) shown in the “Info” column are TCP control packets and do not include any data/payload. They are used for handshaking.

Share