Re: [tcpdump-workers] Proposed new pcap format

2004-04-05 Thread Michael Richardson
. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ -BEGIN PGP SIGNATURE- Version

Re: [tcpdump-workers] print-esp, AES

2004-04-05 Thread Michael Richardson
, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ -BEGIN PGP SIGNATURE

[tcpdump-workers] Bill Fenner: Did this message ever make it to the tcpdump list?

2004-04-07 Thread Michael Richardson
From: Bill Fenner [EMAIL PROTECTED] Subject: Re: [tcpdump-workers] aclocal.m4 and openssl Date: Mon, 5 Apr 2004 11:05:36 -0800 To: [EMAIL PROTECTED] I've been meaning to revisit aclocal.m4 and the autoconf setup for a long time. Much of it was hand-spun to get around bugs or limitations in

Re: [tcpdump-workers] bpf/pcap performance

2004-04-12 Thread Michael Richardson
book.) Dareen, can you suggest a better interface? One that is friendly to C++ without requiring that we drag in any C++ code? -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL

Re: [tcpdump-workers] Proposed new pcap format

2004-04-16 Thread Michael Richardson
than it was in 1995. Fulvio In IETF usuully there is an option which is mandatory Fulvio (often the simplest one), while the remaining are Fulvio optional. Only for standards track :-) - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael

Re: [tcpdump-workers] pcap1.0

2004-05-16 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- I hosted a BOF on Saturday morning about libpcap 1.0 at bsdcan.org. Here are the notes that I took. A lot of people were very interested in helping with this. I hope they will soon be on the list. LINKTYPE enumeration. - metadata about linktype in file.

[tcpdump-workers] web stats

2004-06-03 Thread Michael Richardson
Is there a volunteer that might want to collect the apache logs from all the various tcpdump.org mirrors, combine them and summarize things every month or quarter? A typo in my /etc/newsyslog.conf just filled the /tcpdump partition with the log file (it wasn't getting rolled). - This is the

Re: [tcpdump-workers] [PATCH] Drop unneeded capabilities

2004-06-24 Thread Michael Richardson
if they are non-root. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU

Re: [tcpdump-workers] text format stability

2004-06-25 Thread Michael Richardson
went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy

[tcpdump-workers] anoncvs

2004-06-28 Thread Michael Richardson
- The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ -BEGIN PGP SIGNATURE

[tcpdump-workers] new capture file format

2004-06-30 Thread Michael Richardson
to come and take a look. Other than that, we just need to find someone willing to take notes and issue revised proposals. There is no point in writing code until then. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance

Re: [tcpdump-workers] text format stability

2004-06-30 Thread Michael Richardson
the difference between: 1) invalid 2) valid 3) not enough data Again, if scripts want a stable format, then we need a field=value format. Anything else is going to change at some point. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael

[tcpdump-workers] XML dissector output

2004-06-30 Thread Michael Richardson
each level of dissector register a print function as well? (with XML output all using the common XML print function?) Or is some other structure that someone can think of. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance

Re: [tcpdump-workers] text format stability

2004-06-30 Thread Michael Richardson
? - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security

Re: [tcpdump-workers] tcpdump-current.tar.gz

2004-07-03 Thread Michael Richardson
, but limited it by hosts.allow. I'll rejig stuff a bit. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver

[tcpdump-workers] spam to tcpdump-announce

2004-07-07 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Sorry, I noticed that tcpdump-announce was open to spammers. It is closed now. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED

Re: [tcpdump-workers] Tcpdump time discrepancy (vs ethereal/tcptrace)

2004-07-22 Thread Michael Richardson
is appropriate to the time of the first packet, not to Guy the time when tcpdump called time() in gmt2local(). I think your analysis is right. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa

Re: [tcpdump-workers]

2004-09-07 Thread Michael Richardson
From: [EMAIL PROTECTED] [1. text/plain] drugs? ... [2. application/x-zip-compressed; regid_object.zip]... [3. text/plain] Henceforth, only text/plain will be permitted on the list. -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson

Re: [tcpdump-workers] Trace conversion.

2004-09-17 Thread Michael Richardson
be too hard if the tcpdump format was Paul specified, but if it is, I can't find such a document. get libpcap source, and read pcap.h and pcap.3 - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa

Re: [tcpdump-workers] tcpdump with Linux 2.6 and ipsec/ESP

2004-10-05 Thread Michael Richardson
fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ -BEGIN PGP

Re: [tcpdump-workers] tcpdump -E doesn't work for 3des-cbc/hmac-md5

2004-10-05 Thread Michael Richardson
. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking

Re: [tcpdump-workers] Bad PGP signatures

2004-10-09 Thread Michael Richardson
: There is no indication that the signature belongs to the owner. Primary key fingerprint: 0227 54EB 4C30 9185 FD31 33A3 464D 3CEB 89E9 17F3 - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect

Re: [tcpdump-workers] IPSEC question

2004-10-17 Thread Michael Richardson
to skip the AH header and parse the higher layer Narayanan headers (e.g., TCP) as usual. Narayanan Any help is appreciated. There is no option, it should just happen. Did you try it? -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson

Re: [tcpdump-workers] dealing with collisions, dropped packets

2004-11-01 Thread Michael Richardson
Well, you need to ask your operating system about that. tcpdump runs on about a dozen different systems. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http

Re: [tcpdump-workers] dealing with collisions, dropped packets

2004-11-01 Thread Michael Richardson
are Aaron also available. Those are transmit side collisions. - -- ] Elmo went to the wrong fundraiser - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device

Re: [tcpdump-workers] can't do CVS checkouts/updates anymore

2005-02-07 Thread Michael Richardson
have a static. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ] panic(Just another Debian GNU/Linux

Re: [tcpdump-workers] displaying package content only

2005-02-09 Thread Michael Richardson
. sascha can anyone help me in tweaking? Use snort or dsniff. -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device

[tcpdump-workers] FYI: I'm lame

2005-03-22 Thread Michael Richardson
anymore, so I may not read it in a timely way. I'm not reading tcpdump-workers via gmane.org. I try to catch up once a week, so if it is critical, please email me. Please try to PGP sign, as that gets my highest attention. - -- ] Michael Richardson Xelerance Corporation, Ottawa

Re: [tcpdump-workers] HTTP Auth filter

2005-03-30 Thread Michael Richardson
- -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel

[tcpdump-workers] preperation for 3.9 branch

2005-04-04 Thread Michael Richardson
) verify builds on various platforms d) gather any updates from distro maintainers e) update freshmeat. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http

Re: [tcpdump-workers] libpcap Patches and Release Cycle?

2005-04-06 Thread Michael Richardson
(the link to GSE the source is broken btw). What is the normal delay before GSE formal release? I said we'd branch on April 10, release around the 30th. The branch is early, for self-interested reasons :-) - -- ] Michael Richardson Xelerance Corporation, Ottawa

Re: [tcpdump-workers] fddipad on NetBSD

2005-04-06 Thread Michael Richardson
FDDIPAD in anything under /usr/include on my system. Guy elsewhere (or perhaps the code didn't even compile on those Guy versions - did you try it on 2.0, for example?). - This is the I have yet to upgrade anything to 2.0, which is on my todo list. - -- ] Michael Richardson

Re: [tcpdump-workers] Welcome to the tcpdump-workers list!

2005-04-12 Thread Michael Richardson
that libdnet supports sending on an infinite more than libpcap. Use the right tool for the job. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr

[tcpdump-workers] spam on tcpdump-workers list

2005-04-12 Thread Michael Richardson
. -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking

Re: [tcpdump-workers] Mailing List Info/Procedural Questions

2005-04-15 Thread Michael Richardson
all might have just answered last Jeff month. Hmm. looks like something broke. visit lists.ox.org, and select lists.tcpdump.org, login with your list password, and you can see the archives there. I'll have to fix that. Also, gmane.org has everything. - -- ] Michael Richardson

Re: [tcpdump-workers] preperation for 3.9 branch

2005-04-25 Thread Michael Richardson
gather that there is some new vulnerability that needs to be addressed. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training

Re: [tcpdump-workers] (3) tcpdump infinite loop bugs... (2 fixed

2005-04-25 Thread Michael Richardson
, Romain though... did you? btw, do we have exploit packets in CVS yet? (under tests/) I'd like to see them as regression test cases... - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net

[tcpdump-workers] hold up on 3.9

2005-06-02 Thread Michael Richardson
diapers to change... - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ]I'm a dad

[tcpdump-workers] any objection to -P flag -- exit after packet limit

2005-06-04 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- I added the -P flag, which takes a positive number, and has tcpdump exit after capturing that many packets. It can be combined with the -C flag, but it doesn't cause it to cycle after that many packets, rather the two work independantly. I found I wanted

[tcpdump-workers] 3.9.1

2005-07-05 Thread Michael Richardson
every platform, including improved 64bit support MSDOS Support Add support for sending packets OpenBSD pf format support IrDA capture (Linux only) - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-05 Thread Michael Richardson
. Guy, can you defend this change? - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-05 Thread Michael Richardson
that shows what you want, and put it in the tests subdir? I.e. same input, each possible -x,-X,-A combination, and your expected output. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-06 Thread Michael Richardson
those files to HEAD. Now, we need to commit the fix :-) - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-06 Thread Michael Richardson
. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ]I'm a dad: http://www.sandelman.ca/lrmr

Re: [tcpdump-workers] detecting libpcap 0.9

2005-07-06 Thread Michael Richardson
to release 0.9.2 with these API changes Romain and encourage people not to use 0.9.1... If it happens this week, I'm fine with that. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect

Re: [tcpdump-workers] tcpdump 3.9.1 under Windows

2005-07-06 Thread Michael Richardson
to go out on Sunday, if we can do that. Please pull up what you need to the branch. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com

[tcpdump-workers] 0.9.2/3.9.2

2005-07-10 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Any objection to 0.9.2 going out in the next 20 hours? - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr

Re: [tcpdump-workers] 0.9.2/3.9.2

2005-07-11 Thread Michael Richardson
? - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ]I'm a dad: http

Re: [tcpdump-workers] release 0.9.2/3.9.2

2005-07-11 Thread Michael Richardson
, or Romain something. Romain Looks great otherwise! Oops. marajade-[/mara7/tcpdump/3.9] mcr 1061 %md5sum *.tar.gz 30a9ec79265127f2a2153498ef58bd54 libpcap-0.9.2.tar.gz 6dac4e01a005cc22904f5a7d3c69f769 tcpdump-3.9.2.tar.gz - -- ] Michael Richardson Xelerance Corporation, Ottawa

Re: [tcpdump-workers] 3.9.x

2005-07-14 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- I will do a new 3.9.3, and sign it. Numbers are cheap. marajade-[/mara7/tcpdump/3.9] mcr 1057 %md5sum *.9.3.tar.gz 0ad921c881fdd3d278046afcd352a151 libpcap-0.9.3.tar.gz 26c2f6405d6a94f1160a83109b2f71dd tcpdump-3.9.3.tar.gz Web site updated. - -- ] Michael

Re: [tcpdump-workers] 3.9.x

2005-07-15 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Romain == Romain Francoise [EMAIL PROTECTED] writes: I will do a new 3.9.3, and sign it. Romain The VERSION files are still at x.9.2... Sigh. Sorry. I'm not going to fix this. Let's wait for a bug report. - -- ] Michael Richardson

Re: [tcpdump-workers] Pings fail unless tcpdump is watching both

2005-08-17 Thread Michael Richardson
promiscuous mode (so they can do the multiple-ip filtering) Burton and do not report same to the kernel. I think that you mean, multiple MACs ? - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see

Re: [tcpdump-workers] 0.9.4/3.9.4 release?

2005-08-19 Thread Michael Richardson
. Hannes i have not yet done the printers for those (but that should Hannes be straightforward) can you give me the weekend to complete Hannes those, pls ? yes. -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec

[tcpdump-workers] [tcpdump-announce] tcpdump 3.9.4

2005-10-03 Thread Michael Richardson
) = 4b64755bbc8ba1af49c747271a6df5b8 I hope the version is correct this time, and I think that all the pull ups have been done properly. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED

[tcpdump-workers] www.tcpdump.org

2005-10-12 Thread Michael Richardson
. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking

[tcpdump-workers] downtown for cvs

2005-11-16 Thread Michael Richardson
[ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.1 (GNU/Linux

Re: [tcpdump-workers] where to get libpcap-ng?

2006-01-12 Thread Michael Richardson
related. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using

Re: [tcpdump-workers] Multi process sniffing and dropped packets

2006-01-12 Thread Michael Richardson
-robin performance. Since you are fork()'ing you have no thread issues. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr

[tcpdump-workers] testing the list

2006-02-16 Thread Michael Richardson
This is another test of the mailing list. - This is the tcpdump-workers list. Visit https://lists.sandelman.ca/ to unsubscribe.

Re: [tcpdump-workers] testing the list

2006-02-16 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Michael == Michael Richardson [EMAIL PROTECTED] writes: Michael This is another test of the mailing list. I don't know what I did wrong. But, it is fixed now. A kind gentleman was doing the spam moderation on the list last year. He went

[tcpdump-workers] tcpdump.org

2006-02-16 Thread Michael Richardson
userids @tcpdump.org, continuously hit from 5-10 hosts, greylisting has minimal effect, since I 451 things I won't relay) - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL

[tcpdump-workers] (slightly off-topic) looking for liveCD based packet generator

2006-06-19 Thread Michael Richardson
. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ The Microsoft _Get the Facts

[tcpdump-workers] installing tcpdump with a version number

2006-06-19 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I have various scripts and regression test cases that depend upon specific versions of tcpdump. So, I often install it with a version number as well. I install it twice. Alternatively, a symlink could be changed. This no doubt would mess up

[tcpdump-workers] [tcpdump-announce] tcpdump and libpcap x.9.5 released

2006-09-19 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thanks to Ken Bantoft for updating the CHANGES file. marajade-[/mara7/tcpdump/3.9/f] mcr 1153 %sha1sum *.tar.gz 3a3b0821f7201b4a72201c69ca2411a3db8a83c3 libpcap-0.9.5.tar.gz a9850177809196008ed3e6212cb651ed1500353c tcpdump-3.9.5.tar.gz

Re: [tcpdump-workers] [PATCH] enable sniff on USB ports on linux

2006-09-28 Thread Michael Richardson
them in pcap.h? Guy The licensing issue also applies to pcap-usb.c. I think that we can: a) ask LBL folks if we can move to 3-clause. b) ping all people in CREDITS, and wait a month. - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael

Re: [tcpdump-workers] [RESEND][PATCH] enable sniff on USB ports

2006-10-04 Thread Michael Richardson
to create Stephen lock directory for `/tcpdump/master/libpcap/pcap' Stephen (/tcpdump/master/libpcap/pcap/#cvs.lock): Permission denied Appologies. the lockdir stuff got lost. Try now. - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson

Re: [tcpdump-workers] problem with relay server using pcap

2006-10-11 Thread Michael Richardson
are duplicating the packets? - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian

Re: [tcpdump-workers] I would like to 'request a link- layer type value for WiMax'

2006-11-08 Thread Michael Richardson
::mailto:[EMAIL PROTECTED] @bah.com - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another

Re: [tcpdump-workers] USB support in libpcap

2007-03-26 Thread Michael Richardson
, why not just capture the 802.11 frames themselves into the already standardized frame formats we have? - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http

Re: [tcpdump-workers] [Wireshark-users] Filtering both vlan-tagged as untagged frames with an ip-filter

2007-05-02 Thread Michael Richardson
? If so, I'm Joerg willing to produce one. I don't think the syntax should go into pcap(3). If you want to create a new man page, I think that's reasonable. - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation

Re: [tcpdump-workers] tcpdump v3.9.6 archive incorrect version ?

2007-07-09 Thread Michael Richardson
. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ -BEGIN PGP SIGNATURE

[tcpdump-workers] removing weeklies

2007-07-23 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Is there any objection to removing weekly tar balls from http://www.tcpdump.org/weekly/ that are more than 1 year older than the last release? - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson

[tcpdump-workers] [tcpdump-announce] version 3.9.7

2007-07-23 Thread Michael Richardson
0e2e494d8a66dd644fff03dcad7887164aef9b0e libpcap-0.9.7.tar.gz 5d2a95f0de1cbae70ba01c64f9a2c0fac0183dba tcpdump-3.9.7.tar.gz - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http

[tcpdump-workers] change of IP for bpf.tcpdump.org

2007-10-31 Thread Michael Richardson
just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy

Re: [tcpdump-workers] Changes to the web-page

2007-11-07 Thread Michael Richardson
reports were also sent to the Luis list. Is this possible? The problem is spam. The list machine is not the CVS/web server, so the archives have to be copied manually. -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance

Re: [tcpdump-workers] About some libpcap patches

2007-11-15 Thread Michael Richardson
post the patch to the sourceforge site if they want, as it is more likely that the patch is intact. However, it's very important to post a note to the list explaining what and why. - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson

Re: [tcpdump-workers] tcpdump in c programm

2007-11-18 Thread Michael Richardson
, and will produce output to a fprintf-like function (which could be a string append function for another program). This is a work in-progress. - -- ]Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect

Re: [tcpdump-workers] supporting extend 'open live capture' parametes

2008-01-13 Thread Michael Richardson
don't see a reason to have this array of pcap_opthdr. - -- ] Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ]panic

Re: [tcpdump-workers] supporting extend 'open live capture' parametes

2008-01-13 Thread Michael Richardson
to extend an interface. - -- ] Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ]panic(Just another Debian GNU/Linux

Re: [tcpdump-workers] supporting extend 'open live capture' parametes

2008-01-14 Thread Michael Richardson
form, in the hope Abeni to make the discussion/analysis easier (at least to Abeni me...). What do you think? I think it's a great idea. -- ] Bear: Me, I'm just the shape of a bear. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net

Re: [tcpdump-workers] Web site down

2008-03-28 Thread Michael Richardson
I will take a look at it. You may find a mirror is still alive: www.br.tcpdump.org, www.jp.tcpdump.org etc. - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.

Re: [tcpdump-workers] [Patch] tcpdump probabilistic sampling

2008-04-14 Thread Michael Richardson
Guy == Guy Harris [EMAIL PROTECTED] writes: Guy Michael Richardson wrote: Only... -P is used somewhere else, in another patch, I think. We gotta get 4.0 out, with long options... Guy tcpdump currently still uses getopt(), so it doesn't support Guy long options. Guy

[tcpdump-workers] mirrors

2008-06-23 Thread Michael Richardson
not answer right now. remove? www.my leads to broken system, removed. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http

[tcpdump-workers] bpf.tcpdump.org

2008-06-24 Thread Michael Richardson
. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ - This is the tcpdump

Re: [tcpdump-workers] mirrors

2008-06-24 Thread Michael Richardson
is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy

[tcpdump-workers] bpf down

2008-07-22 Thread Michael Richardson
. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking

Re: [tcpdump-workers] tcpdump.org/release/ is down

2008-09-02 Thread Michael Richardson
not right now) -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel

Re: [tcpdump-workers] Capturing without having superuser rights

2008-10-14 Thread Michael Richardson
the trick, on others (Linux), I don't think there is a way to avoid root. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device

Re: [tcpdump-workers] MIME type for libpcap-format capture files

2008-10-23 Thread Michael Richardson
. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ - This is the tcpdump-workers

Re: [tcpdump-workers] MIME type for libpcap-format capture files

2008-10-23 Thread Michael Richardson
. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ - This is the tcpdump

Re: [tcpdump-workers] tcpdump 4.0.0rc3 and libpcap 1.0.0rc3 now available

2008-10-27 Thread Michael Richardson
I tried building the library before signing it: marajade-[Misc/tcpdump/4.0/libpcap-1.0.0] mcr 1039 %make gcc -O2 -fPIC -I. -DHAVE_CONFIG_H -D_U_=__attribute__((unused)) -c ./pcap-linux.c ./pcap-linux.c: In function 'pcap_read_packet': ./pcap-linux.c:653: error: invalid application of 'sizeof'

[tcpdump-workers] git repo

2008-11-05 Thread Michael Richardson
: error: pcap/usb.h: No such file or directory It might be that I'm missing some pieces/branches. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http

Re: [tcpdump-workers] libpcap-1.0.0 sita configure check

2008-11-05 Thread Michael Richardson
. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy

[tcpdump-workers] --disable-ipv6 and git trees

2008-11-07 Thread Michael Richardson
job. I will import additional things tonight. I did not get any feedback about moving to git. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http

Re: [tcpdump-workers] Linux input layer evdev capturing

2008-11-09 Thread Michael Richardson
event system. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel

Re: [tcpdump-workers] git trees

2008-11-10 Thread Michael Richardson
} and at github, updated nightly. I updated the tcpdump_current (daily snapshots) to pull from git. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http

Re: [tcpdump-workers] Linux input layer evdev capturing

2008-11-13 Thread Michael Richardson
? -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy

Re: [tcpdump-workers] Linux input layer evdev capturing

2008-11-14 Thread Michael Richardson
that gone into a tree somwhere (I can't see it on the David default CVS branch)? Not in CVS at this point. http://github.com/mcr/libpcap/commit/bfb8369657376d58ff54a4a0e64adc86900c2327 -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson

Re: [tcpdump-workers] git repo

2008-11-15 Thread Michael Richardson
Guy == Guy Harris [EMAIL PROTECTED] writes: Guy Unless I'm missing something, a lot of the history seems to Guy have gotten lost. For example, git log pcap-bpf.c shows: commit a9ff5b3dcf3eb90f519c70b4be5cd202190b6ce9 Author: Michael Richardson [EMAIL PROTECTED] Date: Sun Nov

Re: [tcpdump-workers] Linux input layer evdev capturing

2008-11-17 Thread Michael Richardson
. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ - This is the tcpdump-workers list. Visit

  1   2   3   4   5   >