[Wireshark-dev] Setup the filter as string instead of frame[start offset:length]

2012-08-10 Thread Kumar, Chandan (Chandan)
Could you, please help me to make change in Wireshark so that I would be able to select IE by means of filter like others element? I want to make IE's as a filterable field instead of displaying frame [start offset: length] I Did some change for this into epan/proto.c file in Wireshark - 1.6.2

Re: [Wireshark-dev] Setup the filter as string instead of frame[start offset:length]

2012-08-10 Thread Pascal Quantin
Le 10 août 2012 à 08:20, Kumar, Chandan (Chandan) chandan.ku...@alcatel-lucent.com a écrit : Could you, please help me to make change in Wireshark so that I would be able to select IE by means of filter like others element? I want to make IE’s as a filterable field instead of displaying

Re: [Wireshark-dev] Kasumi code (Was: rev 44384: ... kasumi.h ...)

2012-08-10 Thread Jacob Nordgren
Hi. Well perhaps someone then can add KASUMI later on, or even better perhaps an permission from ETSI could be secured in the future. :D I do however want to stress that we have labeled UMTS decryption as experimental and thats probably a bit of an understatement, since we only have one

Re: [Wireshark-dev] Kasumi code (Was: rev 44384: ... kasumi.h ...)

2012-08-10 Thread Joerg Mayer
On Fri, Aug 10, 2012 at 10:06:20AM +0200, Jacob Nordgren wrote: Btw. completly unrelated; How does the wireshark wiki work? should we update the pages for the protocols that we have changed or how does that work? Well, we have a wiki page explaining that :-) http://wiki.wireshark.org/HowToEdit

Re: [Wireshark-dev] Skype protocol dissector

2012-08-10 Thread Joerg Mayer
Hello Matthias, On Thu, Aug 09, 2012 at 10:47:56AM +0200, Matthias Bock wrote: there is a project at GitHub, uncovering the protocol structure of Skype. Currently only UDP is documented (there is also a TCP component somehow).

[Wireshark-dev] FSF address in source files (Was: [Wireshark-commits] rev 44417: ...)

2012-08-10 Thread Joerg Mayer
On Fri, Aug 10, 2012 at 09:28:23AM +, etx...@wireshark.org wrote: http://anonsvn.wireshark.org/viewvc/viewvc.cgi?view=revrevision=44417 ... Copy over Revision 43536 Update Free Software Foundation address. Compability macros from Revision 43728 Revision 43734 Revision 43735 Revision

[Wireshark-dev] DeviceNet dissector

2012-08-10 Thread Hans-Jörgen Gunnarsson
Hello! We are trying to develop a dissector for DeviceNet. We want it to work in Windows and have made some progress. We have constructed software that takes DeviceNet messages from the CAN-network through an IXXAT USB-to-CAN-dongle and transforms them to Ethernet where it can be picked up by

[Wireshark-dev] Packets in different VLANS flagged as duplicated Packets in RTP Stream Analysis

2012-08-10 Thread John Powell
Hi Everyone, I am running Dumpcap as a service. My users have told me that when they select a packet capture then select Telephony - RTP - Show all Streams that it indicates packets are being duplicated (negative packet loss). For the packets being duplicated (negative packet loss), I

Re: [Wireshark-dev] Packets in different VLANS flagged as duplicated Packets in RTP Stream Analysis

2012-08-10 Thread John Powell
Hi Everyone, I should have noted the following: - I am running Wireshark 1.8.1 (compiled from source) under CentOS 6.3. - Dumpcap command command line is: /usr/local/bin/dumpcap -B 32 -i 2 -f vlan and (not vrrp and not udp port 1985 and not ether host 01:00:0c:cc:cc:cc) -b files:1200

Re: [Wireshark-dev] Packets in different VLANS flagged as duplicated Packets in RTP Stream Analysis

2012-08-10 Thread mmann78
I believe you're referring to this bug: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4561 -Original Message- From: John Powell jrp...@gmail.com To: Developer support list for Wireshark wireshark-dev@wireshark.org Sent: Fri, Aug 10, 2012 8:58 am Subject: Re: [Wireshark-dev]

[Wireshark-dev] Determining Cause for Packet Loss in Wireshark 1.8.1 running under CentOS 6.3

2012-08-10 Thread John Powell
Hi Everyone, - I am running Wireshark 1.8.1 (compiled from source) under CentOS 6.3. - I am running Dumpcap as a service. Dumpcap command command line is: /usr/local/bin/dumpcap -B 32 -i 2 -f vlan and (not vrrp and not udp port 1985 and not ether host 01:00:0c:cc:cc:cc) -b files:1200

Re: [Wireshark-dev] Packets in different VLANS flagged as duplicated Packets in RTP Stream Analysis

2012-08-10 Thread John Powell
That certainly does look the same scenario - as the last update was 2010 can I assume that this will not be fixed any time soon? On Fri, Aug 10, 2012 at 7:10 AM, mman...@netscape.net wrote: I believe you're referring to this bug: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4561

Re: [Wireshark-dev] DeviceNet dissector

2012-08-10 Thread Yegor Yefremov
On Fri, Aug 10, 2012 at 1:57 PM, Hans-Jörgen Gunnarsson h...@hms.se wrote: Hello! We are trying to develop a dissector for DeviceNet. We want it to work in Windows and have made some progress. We have constructed software that takes DeviceNet messages from the CAN-network through an IXXAT

Re: [Wireshark-dev] Determining Cause for Packet Loss in Wireshark 1.8.1 running under CentOS 6.3

2012-08-10 Thread Michael Tuexen
On Aug 10, 2012, at 3:14 PM, John Powell wrote: Hi Everyone, • I am running Wireshark 1.8.1 (compiled from source) under CentOS 6.3. • I am running Dumpcap as a service. Dumpcap command command line is: /usr/local/bin/dumpcap -B 32 -i 2 -f vlan and (not vrrp and not udp

Re: [Wireshark-dev] DeviceNet dissector

2012-08-10 Thread Kurt Knochner
Hans-Jörgen Gunnarsson wrote: We are trying to develop a dissector for DeviceNet. We want it to ... and partly decodes them. The problem is that it might be better to pick the DeviceNet-messages directly from the dongle into Wireshark. Perhaps through SocketCAN or something like that. ...

Re: [Wireshark-dev] [Wireshark-bugs] [Bug 3884] Assertion caused by fuzz test file

2012-08-10 Thread Gerald Combs
On 8/10/12 3:23 PM, bugzilla-dae...@wireshark.org wrote: @@ -166,6 +166,10 @@ expert_set_info_vformat(packet_info *pinfo, proto_item *pi,. + if (pinfo == NULL pi-tree_data) + pinfo = PTREE_DATA(pi)-pinfo; Gerald, does it work when dissecting without tree? I'm afraid it