libpcap doesnt provide functionalities like that..
it just gives you the packet as it is.. it is upto us to do the rest :))

You will be well off if you can have a look at open source codes
like bro or snort to see how they do ip fragmentation reassembly or tcp
reassembly !!

bro is also a network based IDS...

-ashley thomas



On Wed, 22 May 2002 [EMAIL PROTECTED] wrote:

> Hi, pals!
>
> I have used libpcap to dump a series of IP packages and got the
> whole payload. And now I want to reassemble the packages. Are
> there any tools from libpcap that I can use?
>
> If there are not related tools in libpcap, can you tell me whether
> there are some other tools that I can use together with libpcap?
>
> Best regards,
> George Ma
> -
> This is the TCPDUMP workers list. It is archived at
> http://www.tcpdump.org/lists/workers/index.html
> To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe
>

-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe

Reply via email to