Antoon Huiskens wrote:
On 02/ 3/10 11:23 AM, Darren Reed wrote:
Rather than the usual 14 bytes, you've got 18 bytes prepended to your
IP packets.
The confusing part is the 2 bytes in front of the MAC addresses and
the 2 bytes between the MAC addresses and the ethernet type.
given that my network works (I observe this whilst typing this email
on the laptop that has the defect) and also snoop does the right
thing, I'd say this looks like a defect in libpcap or?
libpcap and tcpdump, etc, do not modify the data they receive, they just
print it out.
Similarly, bpf should only be recording what it receives from the driver/IP.
These all appear to be broadcast packets of one type or another.
Here's a few more (http requests to blogs.sun.com) I have a hard time
creating a filter that makes sense though:-)
Of course, for some reason there is 4 bytes in there that should not be
there.
Darren
_______________________________________________
networking-discuss mailing list
[email protected]