Re: [Ethereal-users] Capture performance testing

2003-12-04 Thread Chris Rapier
[EMAIL PROTECTED] wrote: Has anyone done any serious performance testing of Ethereal/libpcap/tcpdump as regards network capture performance? I'm curious if there have been any studies done as to how well the capture lib holds up under various network load conditions on various platforms -

[Ethereal-users] Capturing UDP packets between two windows apps

2003-12-04 Thread neil . punia
Is it possible to capture packets between to windows programs running on the same computer using Ethereal? The applications are configured to send to the same IP address but different ports. If not Ethereal, is there another program that gives similar filtering capabilities, that does

[Ethereal-users] Capture with cisco aironet lan adaptor

2003-12-04 Thread Sam Becker
Why can i capture with a wired lan adaptor but not a wireless adaptor? thanks, Sam

Re: [Ethereal-users] Missing apply button in Display Filters

2003-12-04 Thread Guy Harris
On Mon, Mar 10, 2003 at 05:19:45PM -0600, Al Hume wrote: I am tring to take a look at my first capture using Ethereal and I have run into a difficulty with the Display Filters. In the user guide an Apply button is shown on beside the Save and Close buttons on the panel for editing display

[Ethereal-users] filter

2003-12-04 Thread MaRiO
Hi,i want to make a filter that value rtt between voice packet incapsulated in UDP, concerning h323 standard. How can i do? Thank you

RE: [Ethereal-users] 802.11 Initialization vector

2003-12-04 Thread Richard Urwin
-Original Message- From: guoquan [mailto:[EMAIL PROTECTED] hi, there's something i do not understand when reading an 802.11 frame. how do you read the initialization vector (IV). Ethereal output the IV something like 0xaabbcc (in the middle window). however, on the data

Re: [Ethereal-users] Modem capturing...

2003-12-04 Thread Guy Harris
On Tue, Jan 28, 2003 at 05:39:02PM -, [EMAIL PROTECTED] wrote: I am trying to capture the modem traffic, although it is able to monitor the traffic, the performance of the other applications deter. Like Internet Explorer shows cannot find server when browsing...

Re: [Ethereal-users] beginner question on filtering using tethereal

2003-12-04 Thread Guy Harris
On Sep 15, 2003, at 5:04 PM, Steve Pringle wrote: I'd like to look at all SIP, RDP and UDP traffic on a solaris box.  What is the command line for tethereal that will show only the SIP, RDP and UDP  traffic?   From a brute force perspective I've tried excluding just the telnet traffic, but

Re: [Ethereal-users] tethereal: dump -z statistics without terminatingprocess?

2003-12-04 Thread Ronnie Sahlberg
Currently there is no such feature in tethereal. However, it would not be impossible to add. On unix, one could add a signal handler for SIGUSR1 which would just call the tap draw routine similar to how ethereal regularly calls it. I dont know how to do this in a portable way from win32 as well.

[Ethereal-users] Capturing ATM over T1

2003-12-04 Thread Naveen Kumar Kaushik
Hi all I am trying to see s file containing ATM over T1 traffic in ethereal . I am just able to see time stamp no other info. Can any body explain this. Naveen

[Ethereal-users] help

2003-12-04 Thread Lulleri, Massimo Francesco (massimo)
Title: help Hi, I have a ethereal verion 9.11, I'm using it to see the Voip messages, unfortunately I don't able to see the Q.931 and H.323 when I'm doing the caprure during a Voip call. Please can you help me? Thanks Massimo Lulleri Product Specialist AVAYA Italia s.p.a Tel. +39 02

Re: [Ethereal-users] Ethereal Top Talkers

2003-12-04 Thread Ronnie Sahlberg
Hi. There is no support for this currently in ethereal. However, using some shellscripting and tethereal one can sript something that do this. I have plans to implement this functionality in both ethereal and tethereal soon 'but am a bit tied up with h.323 currently. I should have it finished

RE: [Ethereal-users] Compilation of Etherreal 0.9.9

2003-12-04 Thread Joaquin Henriquez Alzola (REE)
Hi again, I always forget to put my OS but it is Solaris 8. I think that ethereal is only supported for gtk 1.2 nad not for gtk 2.2 I don't knwo why but it is this way. BR, Joaquin -Original Message- From: Martin Regner To: Joaquin Henriquez Alzola (REE) Sent: 1/29/03 8:12 PM

[Ethereal-users] DSL modem USB port

2003-12-04 Thread TaffEvs
I have an ADSL modem with one output USB port, which is obviously plugged into a USB port on my PC. Is there an easy way of converting USB to CAT 5 so I can input to my PC's network card so I can use Ethereal? Running Windows XP Home edition Cheers Noel

[Ethereal-users] What are the protocol descriptions written in?

2003-12-04 Thread james_beattie
Hi, Just wondering what the protocol descriptions are written in? Do users contribute these? cheers-jim.

[Ethereal-users] issue with giop syncscope value

2003-12-04 Thread Nicolas . De_Montbel
Hello everybody, I am new on this tool which seems to be very convenient and complete but I have a problem on decoding one giop request header (response flags). from CORBA3.0 specification : response_flags is set to 0x0 for a SyncScope of NONE and WITH_TRANSPORT. The flag is set to 0x1 for a

Re: [Ethereal-users] Capture filter syntax question

2003-12-04 Thread Martin Regner
Andreas Sikkema wrote: But if there is tcp segmentation, you may not get all messages with that message type. The messages are not sent very fast. But they are quite small, I have, however, not seen that much evidence of the Nagle algorithm, so This has to run, if necessary, for weeks

[Ethereal-users] Capture speed

2003-12-04 Thread Michel Vanden Bossche
Title: Message Hi, If we capture an enterprise traffic on a switch by mirroring all traffic on the port where we capture. What is the maximum speed we can capture without losing packets? Does it depends on the NIC type? Does it depends on the PC processor? On both? Is there a

Re: [Ethereal-users] Capturing MMS

2003-12-04 Thread Guy Harris
On Wed, Oct 01, 2003 at 09:53:00AM +0200, [EMAIL PROTECTED] wrote: I think the answer is yes. I send three HTTP1.1 key-value pairs, CRLFCRLF termination and the m-send-req multipart body. So this is presumably some protocol to be used when talking to an MMS Server, running directly atop TCP;

Re: [Ethereal-users] Ethereal 0.9.13 and WinPcap 3.0 issues

2003-12-04 Thread Joerg Mayer
On Thu, Jun 12, 2003 at 11:33:48AM -0400, Bilan, John wrote: I am running Win2K SP3 and just de-installed WinPcap 2.2 and installed WinPcap 3.0 followed by Ethereal 0.9.13. IIRC the winpcap asks you to reboot between the de-install of 2.2 and the new install of 3.0. Did you do that? Ciao

[Ethereal-users] Bug report for Ethereal 0.9.15

2003-12-04 Thread Baier Ulrich
Hello everybody, I just tested Ethereal 0.9.15 with XP and found some strange behaviour which seems to me to be bugs. You might be interested in having them reported: When capturing data with Enable MAC name resolution turned on, Ethereal hangs after stopping the capture. This can be

Re: [Ethereal-users] Filter Question

2003-12-04 Thread Guy Harris
On Oct 20, 2003, at 11:08 AM, Dinkar Bhat wrote: So it implies that one can't write a filter for capturing whole UDP packets of size MTU One cannot, in fact, write a capture filter to capture all of a UDP packet of a size the MTU if the filter is checking the UDP port number and only passing

[Ethereal-users] Terrible capture rates

2003-12-04 Thread Ian Schorr
Tuesday I performed some more performance testing with Ethereal. I finally got various NICs working on my Redhat Linux test machine (dual-booting Redhat 8 with kernel 2.4.18-14 and Redhat 7.3 with kernel 2.4.18-3), but I'm seeing capture performance much lower than I expect. Using a gigabit

[Ethereal-users] compilation error

2003-12-04 Thread Shai Rubin
Hi there, I'm getting the folowing error: gcc -DINET6 -D_U_=__attribute__((unused)) -Wall -W -g -O2 -I. -I./wiretap -I/usr/local/include -I/usr/include/gtk-1.2 -I/usr/include/glib-1.2 -I/usr/lib/glib/include -I/usr/X11R6/include

[Ethereal-users] can't find path libcrypto.sl.0.0.7 HP 11.00

2003-12-04 Thread g . bright
Hi, I'm tryinig to get tethereal/ethereal to run on an A CLASS hp11.00 system, and have downloaded and instlled the depot from http://hpux.asknet.de/hppd/hpux/Gtk/Applications/ also I've installed all stated dependencies -rw-r- 1 root sys 481280 Oct 2 12:16

Re: [Ethereal-users] Capture filters

2003-12-04 Thread Guy Harris
On Fri, Feb 28, 2003 at 01:09:58PM -0500, Parks, Chauni wrote: I recently created and installed an middleware dissector/plug-in. My question is how can I filter on that protocol that I created? What would I put the capture string. The port number on which the traffic is running. Capture

[Ethereal-users] ftp-data

2003-12-04 Thread Giorgio Mulas
Hi everybody, I performed the following experiment: 3 pc in wi-fi ad hoc mode: two of them exchange an mp3 in ftp binary mode, the third is sniffing (tethereal). Then I apply the filter ftp-data and save the packets. I think the packets are now in ASCII. I convert the saved ASCII

[Ethereal-users] tethereal, jumbo files, and STDIN

2003-12-04 Thread Matt Sisk
Is there any way to have tethereal read from STDIN? I'm having trouble reading from large gziped tcpdump files: tethereal: The file ./tcp..gz could not be opened: Value too large for defined data type. The files in question are 10 to 15 gigs in size. Yet I cannot pipe to tethereal

[Ethereal-users] ISDN

2003-12-04 Thread Willy Robinson
Does anyone know if the latest version of ethereal can capture over an ISDN connection ? ---Outgoing mail is certified Virus Free.Checked by AVG anti-virus system (http://www.grisoft.com).Version: 6.0.497 / Virus Database: 296 - Release Date: 04/07/2003

[Ethereal-users] Pseudo-device that captursnip

2003-12-04 Thread Michael B Allen
Is this really necessary? Pseudo-device that captures on all interfaces: any -- A program should be written to model the concepts of the task it performs rather than the physical world or a process because this maximizes the potential for it to be applied to tasks that are conceptually

Re: [Ethereal-users] Latest Ethereal (0.9.15) can't decode H.225 LCF(location confirm) with alternative endpoints

2003-12-04 Thread Martin Regner
Bilig Oyun wrote: The built-in H.225 dissector in the latest version of Ethereal (0.9.15) can't properly decode a RAS Location Confirm Message with alternative endpoints. However, the H.323 plug-in from www.voice2sniff.org is able to decode it correctly. Attached is 3 LCF packets for your

Re: [ethereal-users] capture interface, windows administrator

2003-12-04 Thread Richard Urwin
On Friday 17 Oct 2003 3:12 pm, Microsoft information wrote: hello I use the ethereal with winpcap 3.01 alpha on my XP Pro box as administrator and my interface is detected automatically and displayed in my capture options interface tab. Works fine as admin. Then I can log in as user not in

[Ethereal-users] Q.931

2003-12-04 Thread Alberto Corradini
good morning, i have a question about etehreal and VoIP traffic; we are setting up aNetwork with a Cisco Gatekeeper and 2 Win 2000 client running MS Netmeeting. Everything works properly but when we try to capture the traffic of a h.323 session, we see the q.931 messagesas [Short Frame],

[Ethereal-users] Incorrect timestamp for Distributed SnifferPro 4.x

2003-12-04 Thread SMITH CHRIS (nrd1czs)
I have files captured by NA's distributed sniffer pro (version 4.2 and 4.5 or .7). When I read them with Ethereal (version 0.9.x) or convert them with editcap, the timestamps are garbled: The day is right; the time is off by hours and the fraction of a second is negative. I've followed the

RE: [Ethereal-users] Ethereal on RH9

2003-12-04 Thread Jim Stevenson
Dear Robert, I use ethereal in a teaching environment (Teaching Linux Systems Administration at Campbell College in Edmonton, Alberta, Canada.) We use it extensivly on RH 8 and RH9 in a wide variety of set ups and don't ever run into problems like those you describe. Most are using the RH rpm

[Ethereal-users] New to list: RADIUS VSA decode?

2003-12-04 Thread Stefan Auweiler
Hello all, I'm new to the list and have seeked through the archive prior to ask here... I got a snoop file from a RADIUS Server, where some Cisco VSAs are in. Is there a solution, to get theses VSAs decoded? I've converted the file to a windows sniffer format and a friend could print it for me

[Ethereal-users] 3GPP2 A10/A11 message decodes?

2003-12-04 Thread Pawel Osiczko
Hello! Would anyone happen to have A10/A11 message plug-in? Thanks, --p

Re: [Ethereal-users] Looking for a new non-switched hub

2003-12-04 Thread Guy Harris
On Thursday, June 26, 2003, at 6:48AM, Ronnie Sahlberg wrote: In order to connect the two hubs internally to eachothers the devices usually implements a 2 port switch that is implemented completely inside the enclosure and connects with one port to the 10mbit physical layer and the other port

[Ethereal-users] selective logging of packet fields

2003-12-04 Thread Krishna N. Ramachandran
Hi, I am interested in logging only certain fields in the ethereal log files. As an example, I may want to log only the IP Identification and IP length fields of all packets that I see. The motivation is to record only those fields I am interested in analyzing, in order to save space. Is this

Re: [Ethereal-users] Will ethereal run on Windows 2000 Terminal Server Mode

2003-12-04 Thread Guy Harris
On Sep 9, 2003, at 8:11 AM, John Ferguson wrote: I get a video error when I try to run it on a windows 2000 server that I access via Terminal Services.  Is there a work-around or configuration change to make? http://www.ethereal.com/faq.html#q5.28 which notes, as others have, that 0.9.14 and

Re: [Ethereal-users] Ethereal crash: RTP

2003-12-04 Thread Per Steinar Iversen
On Mon, 13 Oct 2003, Per Steinar Iversen wrote: On Fri, 10 Oct 2003, Guy Harris wrote: On Fri, Oct 10, 2003 at 09:12:55AM +0200, Per Steinar Iversen wrote: It tried this now and the latest ethereal does not crash - it just complains about Unsupported coded and refuses to save the

[Ethereal-users] tethereal -D output

2003-12-04 Thread Loïc Minier
Hello, [ I'm controlling a tethereal subprocess from a Java program and I wonder in which charset the output of tethereal -D is encoded under Windows, and under unices. ] I wonder if there is a specific format a programmer might expect for the output (besides the number of the

Re: Re: [Ethereal-users] Some problem of ethereal plugin

2003-12-04 Thread Guy Harris
On Thu, Oct 30, 2003 at 02:40:48PM +0800, MaFai wrote: CommandLine: /tethereal -r 200310150600.cap -z mgcp,rtd -V|more It work,and print the following message. But it only decoe the header of the package but not the content. That'd strange - I tried it on an MGCP capture I have, and it

[Ethereal-users] IPsec captures

2003-12-04 Thread Dave Wardle
I can't seem to get Ethereal to capture IPsec ESP packets. I'm running a cisco VPN client on my desktop connecting to a remote VPN concentrator, and I'm running ethereal on my laptop. Both laptop and desktop are connected to a mini-hub. I get a capture of the ISAKMP traffic, but no ESP. Any

RE: [Ethereal-users] Export cap to txt

2003-12-04 Thread Mike Blake-Knox
If you want to export the information you see in the Packet List pane, you can use the print command, choosing Text as the format. If you want to export a field that doesn't show in the Packet List pane, the documentation makes reference to adding columns to the display. I haven't figured out how

RE: [Ethereal-users] CRC-check incorrect with win2000 if traffic goes to the own host

2003-12-04 Thread Richard Urwin
There are two way to circumvent this trouble is, if possible, to reconfigure the network card. So it is, in Network Properties, configure NIC, Advanced tab. For both 3c905 and Intel pro100, although worded differently. the second way is to switch off the offloading feature by introducing

Re: [Ethereal-users] Using ethereal to understan microsoft media server protocol

2003-12-04 Thread Guy Harris
On Tue, Mar 25, 2003 at 02:43:05PM +0100, CAMUNAS,MARIO (HP-Spain,ex1) wrote: Does any of you know if ethereal can be used to understand MMS(microsoft media server)? Ethereal has no dissector for the MMS protocols; they're proprietary and undocumented, and nobody's contributed a dissector

Re: [Ethereal-users] Problem running ethereal

2003-12-04 Thread Richard Urwin
On Wednesday 09 Jul 2003 6:26 pm, you wrote: On Wed, Jul 09, 2003 at 06:21:06PM +0100, Richard Urwin wrote: The technology is coming, but is not quite ready. It's been in the kernel for ages, I think - when *is* it going to be ready? I read up on it the last time you mentioned it. It looks

Re: [Ethereal-users] tcpdump vs ethereal

2003-12-04 Thread Ronnie Sahlberg
- Original Message - From: Martin Heroux Sent: Friday, November 21, 2003 7:59 AM Subject: Re: [Ethereal-users] tcpdump vs ethereal One thing I did which works well, is that I created a RAM disk of 500MB which I mount under /tmp So ethereal capture and write it in RAM... I have 1GB

Re: [Ethereal-users] libpcap file format and two more questions

2003-12-04 Thread Guy Harris
On Thu, Jan 16, 2003 at 08:22:35PM +0300, Vladimir Lancov wrote: 1.If anybody knows, tell me please where can I find description of Ethereal's capture file format (libpcap file)? http://www.tcpdump.org/lists/workers/2002/04/msg00096.html 2. After sniffing RealPlayer, Ethereal produces

Re: [Ethereal-users] LDAP and short frames

2003-12-04 Thread Guy Harris
On Wednesday, September 3, 2003, at 12:08 PM, Distribution Lists wrote: I'm seeing a fair amount of short frame during some LDAP binds/search. What are short frames The consequence of either 1) when capturing, specifying a snapshot length not large enough to capture the entire packet; 2)

[Ethereal-users] Query - Bug reports go where?

2003-12-04 Thread Paul Thrower
Hi folks, Having just downloaded Ethereal 0.9.14 for Win32 to test a SNMP utility I'm writing, I'm convinced I've come across a bug with Ethereal's SNMP protocol decode, and I'd like to report itbut to whom do I address bug reports? If anyone is interested, here's what I've noticed :- When

Re: [Ethereal-users] How to display length

2003-12-04 Thread Guy Harris
On Wed, Apr 02, 2003 at 09:46:30AM +0200, [EMAIL PROTECTED] wrote: When you have filtered the frame, you can print summary in a file, and open it with Excel, but this summary doesn't include the frame's length and it's one of the most information I wanted. Printing detail is not a solution

Re: [Ethereal-users] win32

2003-12-04 Thread Guy Harris
On Nov 3, 2003, at 3:10 PM, Gisle Vanem wrote: But it needs Glib 2.x, GTK+ 2.x, WinPcap and optionally net-SNMP and ADNS libraries. It would need WinPcap to compile it (unless the builder manually changed the config.h or config.h.win32 file), but it shouldn't need WinPcap to run - without

Re: [Ethereal-users] Ethereal not work in PPP link in win2k pro

2003-12-04 Thread Guy Harris
On Sat, May 03, 2003 at 12:01:34AM +0800, [EMAIL PROTECTED] wrote: I would like to confirm if ethereal with winpcap 2.3 really works in PPP link (for example, dial-up link) under win2k professional. Unfortunately, we *can't* confirm it. That's because we can *deny* it:

Re: [Ethereal-users] Question about extracting Tethereal data

2003-12-04 Thread Guy Harris
On Thu, Jan 16, 2003 at 03:25:30PM -0500, Robert Casto wrote: Guy, You are asking ethereal-users, which is the right thing to do, not just asking me, as that would be the wrong thing to do. (It is almost *always* the wrong thing to do to ask only me questions about Ethereal, Tethereal, tcpdump,

Re: [Ethereal-users] capture problem with 0.9.15

2003-12-04 Thread Guy Harris
On Sep 16, 2003, at 10:24 AM, ||It's a bird|| wrote: Anyone encountered the following error with 0.9.15 when stating capture? Surely, the capture cannot be done then. Error: The capture session could not be initiated (driver error: not enough memory to allocate the kernel buffer) That error text

[Ethereal-users] Performance Report

2003-12-04 Thread Stefan Auweiler
Gurus, I have a really big snoop, from where I have report the HTTP round trip time: I filter on (http.request or http.response) to get a list of all related packets. How can I get the following Information (best in a list, one line per conversation) for each conversation: - Starttime -

Re: [Ethereal-users] support for pocket pc?

2003-12-04 Thread Guy Harris
On Fri, Jan 03, 2003 at 09:17:46AM -0800, Jay Dombrowski wrote: I dont see any questions on faq about support for pocket pc. Did I miss it or is there not much interest? Well, perhaps we should add a new item to the FAQ: Q: Does Ethereal work on Windows CE-based machines such as

RE: [Ethereal-users] question

2003-12-04 Thread Richard Urwin
I don't know, myself, but I have a nice big archive of the mailing list here. So here are a few previous messages that you might find helpful. http://www.ethereal.com/lists/ethereal-users/200304/msg00183.html: FWIW From my testing so far: - Ethereal can capture on a loopback address at speeds

Re: [Ethereal-users] Another decode bug?

2003-12-04 Thread Guy Harris
On Thu, Feb 20, 2003 at 04:41:18PM -0600, McNutt, Justin M. wrote: This packet also seems to cause Ethereal to hang (both Windows and Linux). Infinite loop in the COPS decoder? Yes. Not sure if this one has already been discovered; I'm not running the latest CVS snapshot... It hasn't; I've

[Ethereal-users] redhat 8.0 install difficulties with ethereal-0.9.7

2003-12-04 Thread Cameron Hummels
Hello: I've recently installed RedHat 8.0 on a system, and I was trying to load ethereal 0.9.7 onto it. I read the FAQ and looked at previous messages in this userlist, but was unable to find information about the particular problem that is occurring. When I go to install the

[Ethereal-users] Mac filtering

2003-12-04 Thread Kevin Kobe
Title: Mac filtering All, I am a new user to this program and I am having trouble with the Capture Filters. Can anyone tell me how to filter via a mac address? Thanks in advance. Kevin Kobe Systems Engineer

Re: [Ethereal-users] Problem with RSVP filter

2003-12-04 Thread Guy Harris
On Thu, Nov 28, 2002 at 04:50:34PM +, co web wrote: I'm having troubles trying to filter rsvp packets in the latest version of Ethereal for windows 2k. I defined a rsvp filter with the filter name: rsvp, and the filter string: rsvp. When I press start in the capture menu, i get a string

Re: [Ethereal-users] tcpdump vs ethereal

2003-12-04 Thread Ian Schorr
On Nov 19, 2003, at 3:58 PM, Martin Heroux wrote: 1- why does tcpdump don't get the same amount of packets as a regular sniffer (Dolch for instance) I am using one of the best gigabit card on the market I should get the same result. BTW the altheon card can be driven to wire speed, I saw it on

[Ethereal-users] Re: Ethereal-users Digest, Vol 3, Issue 58

2003-12-04 Thread Mark Peart
Testing

RE: [Ethereal-users] Output from tethereal to a .bpf or .enc

2003-12-04 Thread Christopher Lyon
So, The .enc I gather would be the dos based ngsniffer for the .enc but I have no idea what the .bpf would be nor do I know what kind of sniffer that would be from. -Original Message- From: Guy Harris [mailto:[EMAIL PROTECTED] Sent: Monday, June 23, 2003 7:02 PM To: Christopher Lyon

RE: [Ethereal-users] capturing loopback packets

2003-12-04 Thread Jay Chalfant
I meant the former.. and I was afraid you were going to say that. thanks, -J -Original Message- From: Guy Harris [mailto:[EMAIL PROTECTED] Sent: Monday, January 06, 2003 4:05 PM To: Jay Chalfant Cc: '[EMAIL PROTECTED]' Subject: Re: [Ethereal-users] capturing loopback packets

[Ethereal-users] make error with 0.9.15

2003-12-04 Thread Kevin Smith
When a try to make this version in a RH system, 2.4.22 kernel I get the following error: b.o register.o capture.o file.o filters.o proto_hier_stats.o summary.o .libs/etherealS.o -rdynamic -Wl,--export-dynamic -L/usr/local/lib wiretap/libwiretap.a gtk/libui.a epan/libethereal.a

Re: [Ethereal-users] Problem with Ethereal on Dell 2650 Server

2003-12-04 Thread Guy Harris
On Wed, Dec 04, 2002 at 11:35:57PM +0100, [EMAIL PROTECTED] wrote: I have a problem with Ethereal on Dell 2650 Server. In Capture-Start-Interface I haven't got any interface but : singn? Can anybody help me? Yes. Remove the multi-threaded processor from your Dell and replace it with a

[Ethereal-users] Identify OS

2003-12-04 Thread Rufoo
Is there a way to identify the OS (windows 2k vs XP) from the DCERPC or EPM or NSPI or NTLM exchanges? __ Do you Yahoo!? Protect your identity with Yahoo! Mail AddressGuard http://antispam.yahoo.com/whatsnewfree

RE: [Ethereal-users] W2K Laptop

2003-12-04 Thread Mark Holloway
What kind of nic? -Original Message- From: nugrange [mailto:[EMAIL PROTECTED] Sent: Thursday, July 17, 2003 11:08 AM To: [EMAIL PROTECTED] Subject: [Ethereal-users] W2K Laptop Dear List, I have just upgraded my laptop to Win2000 (my first exposure to this OS) and when I try to start

[Ethereal-users] Ethereal capture filter doesn't work

2003-12-04 Thread rluk
Title: Ethereal capture filter doesn't work Hello, I loaded ethereal 0.9.11 on my Win2K-Pro. Installation is smooth and easy. But I hit a problem in capture filter: (1) I click Capture -- Start and enter a capture filter host 192.168.1.3. (2) My ethereal is on 192.168.1.2. (3)

Re: [Ethereal-users] capturing scsi data

2003-12-04 Thread Martin Regner
Hi, I'm quite sure that Ethereal (or actually libpcap/wincap) cannot not capture SCSI traffic. There seems also not to be any support for reading some type of SCSI capture files in Ethereal (if there was some other program/utility that could be used to capture the data). It seems that

Re: [Ethereal-users] Promiscuous mode

2003-12-04 Thread Guy Harris
Anthony Scott said: I am trying to set my NICs in promiscuous mode. I have one Intel Pro 100 and one Intel Pro 1000 on Windows 2K Pro and Server. I can not find any documentation on Intel's site about doing this. Can anyone help me? By set my NICs into promiscuous mode do you mean do a

RE: [Ethereal-users] Filter out LLC protocal packets

2003-12-04 Thread Ow Mun Heng
-Original Message- From: Guy Harris [mailto:[EMAIL PROTECTED] Sent: Thursday, November 20, 2003 11:01 AM And if you want to see IP frames, but not IP frames with DNS traffic in them and not IP frames to or from the machine running Ethereal, then ip !port 53 !host

[Ethereal-users] TCP session printed with packet breaks

2003-12-04 Thread hammygross
Dear All, I've had a good play around with Ethereal and checked out this list's archives, however I couldn't find a way to follow a TCP session (i.e. outputting the packet's contents rather than headers), however with the output showing where each packet starts and ends. Could anyone

[Ethereal-users] Filters Not Saved in Windows

2003-12-04 Thread Tom Trapnell
I installed Ethereal 9.16 on Windows XP. Everything seems to be working fine, except that filters do not get saved when I try to save them. There are no error diagnostics. The filter just disappears. As a result, I have to retype it on the Capture screen every time I run a capture. - Tom

[Ethereal-users] Configuration of Conversation List aka top talkers

2003-12-04 Thread Tim michals
I'm trying to configure ethereal 0.9.15 to display the top talkers, List Of Conversions during a live trace and have been unsucssful in finding the configuration option. Where did I can I find it? Sorry for the simple question __ Do you Yahoo!? Exclusive Video

RE: [Ethereal-users] How to use tethereal to display TCP data?

2003-12-04 Thread Visser, Martin (Sydney)
Title: Message Try using "tethereal -V" Martin Visser ,CISSPNetwork and Security ConsultantTechnology Infrastructure - Consulting IntegrationHP Services3 Richardson PlaceNorth Ryde, Sydney NSW 2113, AustraliaPhone (: +61-2-9022-1670 Mobile : +61-411-254-513 Fax 7: +61-2-9022-1800

RE: [Ethereal-users] reconstruct captured data?

2003-12-04 Thread Mack
Cool! I'll give it a try and post my results thanks, mack On 4 Sep 2003 at 20:11, Darren Forster wrote: Mack, Yes you can do it, you have to go to tools and select follow tcp stream. This will extract the data sent within a specific TCP session. Save the file to another file. Then

Re: [Ethereal-users] how does ethereal determine whether RTP or not?

2003-12-04 Thread Guy Harris
On Sep 5, 2003, at 10:56 AM, Martin Regner wrote: If it was possible to have strings in dissector tables I've checked in changes to let you create, manipulate entries in, and look up dissectors in dissector tables using a string as a key. The way you create them is to specify FT_STRING or

Re: [Ethereal-users] No Packets from Compaq WL100

2003-12-04 Thread Henrique Issamu Terada
David, try to disable promiscuous mode. I made this with my Cisco Aironet, and it worked . Terada Middleton, David gravada: I have two network adapters in a Compaq Armada M700 laptop. I cannot see any packets on the Wireless WL100 Interface. The first adapter listed in Ethereal, the

RE: [Ethereal-users] Automation of Ethereal

2003-12-04 Thread McNutt, Justin M.
shrug Or just don't run Windows. You can get a complete Pentium 4 system from Office Depot for less than $500. Just build a Linux or BSD machine and have done with it. Use Windows for MS Office. :-) --J -Original Message- From: Paul Hoffman / VPNC [mailto:[EMAIL PROTECTED]

[Ethereal-users] Timestamp output to a file?

2003-12-04 Thread Brandes, Sean USA
Title: Timestamp output to a file? Hello, I am relatively new to eathereal and have a question about how one can take portions of the captured data, for example the timestamps, and export that information into a text file? Is there a way to select which data you would like to save and save

[Ethereal-users] Network traffic

2003-12-04 Thread PaulT
Just started using ethereal ( I am using 0.9.8 rpms and have installed ethereal-base, ethereal-gnome, ethereal-usermode, ethereal-gtk+, are there any other packages I should install?), an excellent tool, and am having some trouble seeing all the traffic on my network (about 8 PCs, mostly Windoze,

Re: [Ethereal-users] Capturing on a dial up line

2003-12-04 Thread Martin Regner
Apurva Shukla wrote: Hi all, i am probably posting the request the second time and just wanted to know the reason of not being able to surf anything when i start capturing packets by ethereal . thanks in advance apurva I assume that you are using WinPcap on Windows. Besides the information

[Ethereal-users] key logger embedded in the Win32 install?!

2003-12-04 Thread Michael Fryman
I just downloaded the http://www.ethereal.com/distribution/win32/ethereal-setup-0.9.7.exe file and went to install it, and my PestPatrol Memory Scanner popped up with a message saying that the pest called Family Key Logger 1.10 was detected in memory! What is this? Why are these guys installing

[Ethereal-users] 802.11 support in Windows

2003-12-04 Thread Dave Piscitello
Does anyone know of any effort to support 802.11 packet analysis in windows versions of ethereal? Anyone know of a windows wlan analyzers that do this other than airopeek? David M. Piscitello Core Competence, Inc. 3 Myrtle Bank Lane Hilton Head, SC 29926 [EMAIL PROTECTED] 843.689.5595

Re: [Ethereal-users] capture does not see interfaces using 0.98

2003-12-04 Thread Guy Harris
On Fri, Dec 27, 2002 at 02:02:18PM -0500, Lehrer, Neil (OIG/OAS) wrote: i just installed 0.98 and went to try a capture. the capture dialog does not see my network interface. it worked fine under 0.97. Are you *CERTAIN* that the *ONLY* change you made was to install a new version of

[Ethereal-users] OSPF Extensions in support of GMPLS

2003-12-04 Thread Eduard Escalona
Hi all, I'm implementing the extensions of OSPF for GMPLS. I'm using zebra and ethereal to capture the packets. By now, the only sub-TLV that ethereal detects is the Interface Switching Capability Descriptor (type=15). Is ethereal capable now to capture sub-TLV with type 11, 14 16 as

Re: [Ethereal-users] Command line version for win32?

2003-12-04 Thread Ronnie Sahlberg
try tethereal.exe this is the console version of ethereal which is similar to tcpdump. - Original Message - From: Aman Singer Sent: Monday, July 28, 2003 1:05 AM Subject: [Ethereal-users] Command line version for win32? Hi, all. I just started using Ethereal today, and find the

Re: [Ethereal-users] Problem compiling 0.9.7

2003-12-04 Thread Geoff
On Fri, 15 Nov 2002 11:27:59 -0800 Guy Harris [EMAIL PROTECTED] wrote: On Fri, Nov 15, 2002 at 08:17:29AM +, Geoff wrote: I think my zlib is up-to-date - it is 1.1.4 which (according to http://www.gzip.org/zlib/), is current. What does the commands nm -p /usr/lib/libz.a |

Re: [Ethereal-users] I cannot compile ethereal ethereal-0.9.14 onWin32

2003-12-04 Thread Loïc Minier
Pierre Pacchioni [EMAIL PROTECTED] - Thu, Aug 14, 2003: Any hint? Since these are mostly GLIB functions, I guess your glib is not set correctly. You have to unzip glib-dev and gtk-dev to a directory, and define it in the config.nmake. Extract of my config.nmake: GTK_VERSION=2.0

Re: [Ethereal-users] ECCN Classifications for Open Source Items

2003-12-04 Thread Guy Harris
On Mon, Dec 16, 2002 at 03:51:48PM -0600, Bettley, Carolyn wrote: If it contains encryption, I will need to know if your company has submitted at least a one-time review to the USG for their review, or have already rec'd ENC approval? My company doesn't produce Ethereal. There *IS* no company

[Ethereal-users] Ethereal Shared Libraies Loading Errors

2003-12-04 Thread BUYCK Jacky FTRD/DMI/CAE
Hi all. I just get the following error using Ethereal : Error while loading shared libraries : ethereal undefined symbol : sprint_realloc_objid. It cause my ethereal to simply vanish in the air during the dump simply printing the previous message. I don't

Re: [Ethereal-users] RPM installation

2003-12-04 Thread Guy Harris
On Tue, Mar 04, 2003 at 03:57:42PM +0100, David Fay (LMI) wrote: I don't have the configure command on my PC. It's not a system command, it's a command (shell script, actually) in the source directory of Ethereal (and of many other UNIX programs). So, from the top-level directory, run

[Ethereal-users] Stealth Interface Problems, ifconfig eth0 up???

2003-12-04 Thread Mike Chandler
I must be missing something. I'm trying to get ethereal to run on a stealth interface (with no IP address). I'm using Ethereal 0.9.9 with Redhat 8.0 but I've tried this on 7.2 and 6.0. I'm using libpcap-0.6.2-16 on Redhat 8.0. Iremoved my ifcfg-eth0 entry from

[Ethereal-users] Printing Packets

2003-12-04 Thread michael.2.sweeney
Title: Message What I'd like to do is when I select "Print Packet" for the hexidecimal code to print as well how do i achieve this as when I select print , it prints all the packets + hex code out. basically i want to print out a single packet with hex code on it, how is this achieved

Re: [Ethereal-users] tcpdump is backend?

2003-12-04 Thread Guy Harris
On Thursday, June 19, 2003, at 12:58PM, Joe Acquisto wrote: Any truth to a statement I heard that tcpdump is the backend for ethereal? None whatsoever. Ethereal has its own packet dissecting code, unrelated to tcpdump's packet dissecting code. Ethereal and tcpdump both use the same library to

  1   2   3   4   5   6   7   8   9   10   >