Re: [Ethereal-users] PPP WAN support in win2k

2003-12-04 Thread Guy Harris
On Sep 21, 2003, at 9:29 AM, aa432451 wrote: I have just downloaded your ethereal software. For LAN captures it is OK, but it does not recognize PPP WAN interface in Windows 2000. I know the origin of the problem (WinCap cannot treat NDISWAN). Do you know any solution I can download ? Or

[Ethereal-users] Looking for a new non-switched hub

2003-12-04 Thread J T
Title: Message Hi all - I'm doing some sniffs on my network and need to find a non-switched 10/100 hub (preferably non-auto sensing as well to eliminate any 'smarts' from the device) - Any suggestions? Jeffrey ThrelfallSr. Network AdministratorHealthcare AutomationVOX - 401.691.3240Email

Re: [Ethereal-users] Capture Filters

2003-12-04 Thread mike
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Brad, Yes, You can use any of it that is useful for the project manual. If you would like to collaborate or need any help cleaning it up to match the style of manual, I would love to help out. Just email me off-list and we can take it from

Re: [Ethereal-users] Following a stream using Tethereal

2003-12-04 Thread Ronnie Sahlberg
There is currently no other method than the normal Follow TCP stream. It would be very nice if the HTTP dissector could be updated to parse and understand more of the header so that say content-length: would be parsed and used for tcp-reassembly then the actual data following the \n\n could be

Re: [Ethereal-users] Interbase

2003-12-04 Thread Guy Harris
On Wed, Jan 15, 2003 at 05:33:19PM +, [EMAIL PROTECTED] wrote: I am seeing packets listed as protocol IB or Interbase however these are no IB packets in my capture. Is any one able to detail what ethereal matches packets to to list this as a IB protocol, ie. is it an offset match for a

RE: [Ethereal-users] Possible Protocol Mismatch

2003-12-04 Thread Visser, Martin (Sydney)
Joris, It sounds like you are making some progress (at least from your response to Martin Regner's mail). Be certain that you view Ethereal as a diagnostics tool (with all it's limitations) and not expecting it to give you a final solution. Just as a medical X-ray requires interpretation by

Re: [Ethereal-users] rsync protocol: probably a dumb question...

2003-12-04 Thread Guy Harris
On Friday, August 8, 2003, at 2:03 AM, Brad Hards wrote: The code that I wrote for rsync is really, really rough. The rsync protocol is quite hard to work out - there are no per packet headers, so if you don't have the whole thing, it is very difficult to tell if the packet is showing part of

RE: [Ethereal-users] URGENT: Need help with RTP stream playback issue

2003-12-04 Thread Andrew Lacey
Hello Richard/ All, I am a novice to ethereal, I was wondering how you go about saving the payload of a VoIP (RTP) ethereal capture. I have a Avaya IP403 office plus 4602 IP phone on test, Is it possible? plus then to play the conversation. If you know a good source of VoIP info include the

Re: [Ethereal-users] Supported PT code for RTP Packets

2003-12-04 Thread Martin Regner
* RTP Payload types * Table B.2 / H.225.0 * Also RFC 1890 */ #define PT_PCMU 0 #define PT_1016 1 #define PT_G721 2 #define PT_GSM 3 #define PT_G723 4 #define PT_DVI4_8000 5 #define PT_DVI4_16000 6 #define PT_LPC 7 #define PT_PCMA 8 #define PT_G722 9 #define PT_L16_STEREO 10 #define

Re: [Ethereal-users] (no subject)

2003-12-04 Thread Guy Harris
On Sun, Nov 09, 2003 at 04:30:36PM +0200, Gil Yaacoby wrote: Cellcom ISRAEL ltd. employees are interested in using Ethereal and Winpcap 3.x software . Please confirm by E-mail that this software can be used by our organization's workers for free. See the COPYING file in the Ethereal

[Ethereal-users] Writing Capture/Display filters

2003-12-04 Thread Ronald Nutter
I have been trying to find information on writing filters, both capture and display which look for a specific fingerprint or hex information out of the packet. Can someone show me how to get this done ? Also, can you point me to a reference that shows me the language supported by the ethereal

Re: [Ethereal-users] WildPacket capture to libpcap?

2003-12-04 Thread Joerg Mayer
On Thu, Jun 12, 2003 at 11:37:06AM -0400, Joshua Wright wrote: I have a packet capture I created with the WildPackets AiroPeek NX tool. It opens fine in Ethereal, and all the information decodes properly. Is there a way to convert this file to libpcap format? I tried to save it as a different

[Ethereal-users] Ethernet frame length

2003-12-04 Thread Caprice
Looks like this problem only occurs with the Sygate software firewall,SPF PRo, up and running. I'm working with Sygate now.

Re: [Ethereal-users] doubt about ethereal display

2003-12-04 Thread Guy Harris
(Note: I am on both the ethereal-dev and ethereal-users mailing lists; it is unnecessary to send mail to me personally if you are sending it to either of those lists.) On Wed, Mar 19, 2003 at 04:25:16PM +0530, Mudium, Ravi Kumar (RAVI)** NL ** wrote: Which portion of the code of ethereal is

[Ethereal-users] Libraries versions with ethereal-0.9.16

2003-12-04 Thread Mikko.Ju.Kanerva
Hi! I have ethereal version 0.9.16 and Win32 / MSVC6. Following packages and versions are installed. Do I need some other libraries and are the versions ok? Package Default Location ---

Re: [Ethereal-users] MAC to IP mapping

2003-12-04 Thread ChuckS
Ethernet II, Src: 00:04:00:6c:48:82, Dst: ff:ff:ff:ff:ff:ff Destination: ff:ff:ff:ff:ff:ff (Broadcast) Source: 00:04:00:6c:48:82 (LexmarkI_6c:48:82) Type: Netware IPX/SPX (0x8137) Huh! IPX packets are not IP. True however LexmarkI_6c:48:82 is enough of a clue as to the

[Ethereal-users] PDA

2003-12-04 Thread Dale Worley
Anyone use this on a pocketPC? Dale Worley, CCNA Internet Services Engineer Eagle Broadband Services

RE: [Ethereal-users] Capturing the data from the Switches??

2003-12-04 Thread Grobard, Gary
You need to mirror the port you would like to capture data from. --- Gary S. Grobard MCSE Cornerstone Real Estate Advisers One Financial Plaza, Suite 1700 Hartford, CT 06103 -Original Message- From: Hari TSR [mailto:[EMAIL PROTECTED] Sent:

Re: [Ethereal-users] Help with Install

2003-12-04 Thread Gene
PSYCHE is the code name for RH8.0. PSYCHE also came with Ethereal-0.9.6-1. It may be in your rpm package database. Try this - rpm -q ethereal, just to make sure you don't have it installed. If you don't have it installed you also need to install the GTK. hope this helps. gene Guy Harris

Re: [Ethereal-users] tcpdump vs ethereal

2003-12-04 Thread Guy Harris
On Nov 19, 2003, at 1:25 PM, Ian Schorr wrote: However, Sniffer's Infinistream product is able to capture packets *to disk* at near- full-duplex gigabit speeds without dropping packets with what is essentially high-end PC hardware, ...using patent-pending technology:

Re: [Ethereal-users] network interface not found

2003-12-04 Thread Guy Harris
On Tue, Sep 16, 2003 at 11:11:02AM +0200, Matthias Albus (FF) wrote: I just installed ethereal using tethereal 0.8.18,on my AIX 5.2 machine. When I start with tethereal -i en0 it gives: tethereal: The capture session could not be initiated (/dev/bpf0: A file or directory in the path name

RE: [Ethereal-users] help

2003-12-04 Thread Martin Regner
Massimo Fransecow Lulleri wrote: I have a ethereal verion 9.11, I'm using it to see the Voip messages, unfortunately I don't able to see the Q.931 and H.323 when I'm doing the caprure during a Voip call. Please can you help me? In order to dissect the H.323 messages (H.245/H.225) you'll need the

Re: [Ethereal-users] Performance Report

2003-12-04 Thread Ian Schorr
Currently I don't believe that RTT (SRT, or Service Response Time) is reported by the HTTP dissector, nor by the large majority of protocol dissectors. It definitely wasn't supported in 0.9.9. At some point I'd like to start walking back through some of the more popular dissectors (or better

RE: [Ethereal-users] Lost packets

2003-12-04 Thread Andreas Sikkema
From: David Kuder [mailto:[EMAIL PROTECTED] About the only thing missing is pulling the G.711 payload out of the RTP as an audio stream (aka tapping a call). (From memory) Tools / Statistics / RTP analysis will do that for you. You sure you have a hub? If you see traffic in the capture

Re: [Ethereal-users] newbie question - capture filtering IPX

2003-12-04 Thread Guy Harris
On Thu, Apr 03, 2003 at 12:24:12PM -0500, Matt Hoyle wrote: I'll give the WinPcap 3.0 beta a shot. Note that it *is* a beta, and might, as such, have more bugs than a non-beta version. Bugs should be reported to the WinPcap developers.

[Ethereal-users] Ethereal -- nothing happens

2003-12-04 Thread Jin Ho Tan
Hi all,I installed Ethereal 0.9.8.c (and winpcap 2.3) to capture HTTP traffic from my win2k laptop to a development server. However, when I started to capture from the interface (e.g., \Device\Packet_NdisWanlp), nothing is captured at all. All the statistics showed 0%.I've tried to turn off all

RE: [Ethereal-users] capturing cisco ata186 traffic

2003-12-04 Thread Mat Ford
Guy, Thankyou very much indeed for taking the time to point me to that info - I was well aware of the problems that could be caused by switches or switching hubs, but I wasn't familiar with the problems caused by 10/100Mbps auto-sensing hubs. This was my problem and now that I have my ethereal

[Ethereal-users] refuses to parse HTTP protocol

2003-12-04 Thread Quartz
Hi, I have tried 0.9, 0.9.9, 0.9.11. Could never decode http protocol. What is wrong with it? (it is enabled, not filtered, it just doesn't show up as it does in your snapshots) It shows as TCP, I have to loo at the TCP data all the time Thanks for helping.

[Ethereal-users] Import in Excel

2003-12-04 Thread Michel Vanden Bossche
Title: Message Dear friends, Is it possible to read the capture file with Excel? Yours Sincerely, Michel Vanden Bossche +32(0)477 576 900

[Ethereal-users] Cifs traffic

2003-12-04 Thread von Kuelmer, Ferdinand
Hi all, i try to analyze a cifs trace. Please, how can i set a special filter for cifs requests, responses, close etc. I know the filter expressions for tcp.ports, http.* and all the other normal network traffic, but CIFS seems to be a protocol with a big overhead and and a lot of

Re: [Ethereal-users] SMPP protocol sometimes is not decoded

2003-12-04 Thread martin.regner
Igor i. Shulz wrote: I've last ver (0.9.12) Ethereal installed on my WinXP. It's strange - in all cases that I captured SMPP (Short Message Peer to Peer) packets on this PC they are not decoded (all SMPP-traffic is showed as TCP-protocol and SMPP-content is not decoded). I have file with

[Ethereal-users] Rob Flentge/Mechanicsburg/US/Exel is out of the office.

2003-12-04 Thread Rob Flentge
I will be out of the office starting 09/30/2003 and will not return until 10/03/2003. I will respond to your message when I return. Important Email Information The information in this email is confidential and may be legally privileged. It is intended solely for the addressee. Access to this

Re: [Ethereal-users] Application Keeps Acking Same Packet, then Suddenly Catches Up

2003-12-04 Thread Ronnie Sahlberg
Nagle only comes in to play for things like delayed acks and things. When a segment is received that does not advance the left edge of the receiving window (i.e. out of order), an ACK is to be sent immediately to the other side to inform about the potential packet-loss. No exceptions. Nagle

[Ethereal-users] PPP WAN support in win2k

2003-12-04 Thread aa432451
Dear Sirs: I have just downloaded your ethereal software. For LAN captures it is OK, but it does not recognize PPP WAN interface in Windows 2000. I know the origin of the problem (WinCap cannot treat NDISWAN). Do you know any solution I can download ? Or where is the site that problem is being

RE: [Ethereal-users] URGENT: Need help with RTP stream playback issue

2003-12-04 Thread Andreas Sikkema
On vrijdag 14 november 2003 10:59, Voice Guy wrote: I don't see an option within ethereal to save it as a 16bit stream. Is there a plugin? I am running Ethereal on Windows. Strange, I have had no problems playing back the file using Media Player when I tried the last time. I was using

Re: [Ethereal-users] Extrat IMAP date from a TCP stream

2003-12-04 Thread Guy Harris
On Wednesday, July 9, 2003, at 10:44 AM, Jacky Buyck wrote:         is there another better way to extract application data from a TCP stream You could use the Save As button in the Follow TCP Stream window to save the stream to a file, and then edit the file. Whether that's better is

Re: [Ethereal-users] streaming capture to multiple files

2003-12-04 Thread Guy Harris
On Oct 29, 2003, at 2:16 PM, Ian Schorr wrote: What you can't do currently, however, is instruct Ethereal to stop after it writes a certain number of files or bytes. You can tell it to stop after a certain number of frames, and after a certain number of seconds, but not tell it to record up

[Ethereal-users] How it captures the data of a group?

2003-12-04 Thread Enzo Alvarez
hi I installed ethereal in linux red hat. It´s ok. my networking is separate in group. The group have various PC. the question is: How it captures the data of a group I specify? How it captures the data of a PC I specify? Thank.

[Ethereal-users] how can a novice use Ethereal?

2003-12-04 Thread Russell Cole
Even with 2 years of Basic, "that’s the language", and minimal fundementals, 20 years computer user, I still can't figure out how to use this "brilliant idea" ethereal…. need help with something draining my modem, …. all virus scans show Not…. I am stuck in dead water on the internet while

Re: [Ethereal-users] tcpdump lines to use when capturing

2003-12-04 Thread Guy Harris
On Thursday 08 May 2003 6:19 pm, [EMAIL PROTECTED] wrote: I thought i could do it by entering: ether proto smtp but no such luck.. :/ ether proto smtp won't work at all, as SMTP doesn't directly run atop Ethernet. On Thu, May 08, 2003 at 06:59:38PM +0100, Richard Urwin wrote: Try: port

[Ethereal-users] Is it possible to build a Static Version of Ethereal

2003-12-04 Thread S. Faizi
I would like to build a static version of Ethreal for Solaris. This way I can have all machines share it even if they don't have libcap, libgtk etc. Is there an option in the Makefile for this? Thanks, Sal

Re: [Ethereal-users] Install Probs

2003-12-04 Thread Guy Harris
On Oct 16, 2003, at 2:40 PM, Jonty Ray wrote: However for GLIB after i run ./configure I do not find any make file been created in scratch/users/ukoul/Ethereal/glib-1.2.8, so I have not gone to step 2 3 above. May be that the reason for incomplete GLIB installation. How can I overcome it.

[Ethereal-users] RTP to wave format coversion.

2003-12-04 Thread Poulose, Jacob
Hi, is there any software/plugins available for converting RTP(G711a-law) to wav/mp3/ra files? thanks, -jac

[Ethereal-users] test

2003-12-04 Thread pragmaticcomputing.co.uk
Doug TroupPragmatic Computing e-mail: [EMAIL PROTECTED]messenger: [EMAIL PROTECTED] Please NoteThis e-mail is confidential, and may also be legally privileged. It is

[Ethereal-users] help???????????

2003-12-04 Thread Ka K. Lor
hi there anyone, I was writing a manual of my usage and capturing package..I need the package that I capture to go into my document.. how do I do this and so that I have the screen of ethereal or the all the package that I am capturing into my document, so as i talk about it the example are there

[Ethereal-users] ethereal 0.9.11 on RedHat 8.0 with net-snmp fails on -lelf

2003-12-04 Thread James R. Hendrick
it builds all the .o files, but the link fails on ld -lelf... linking ehtereal. These things come with redhat 8.0: libpcap-0.6.2-16 net-snmp-5.0.6-8.80.2 gcc-3.2-7 etheral-0.9.8-0.80.0 GTK+ 1.2.10 GLib 1.2.0 libz 1.1.4 I built and installed: libpcap-0.7.2 and tried to build

[Ethereal-users] Following a TCP stream

2003-12-04 Thread Don Beal
Hello, I'm trying to track down a problem with a ftp transfer that is 45 megs worth of data. When I follow the tcp stream, only 150,000 lines are created and then it cuts off. I've tried this on different boxes and OS's with the same problem. Is this a known issue? Thanks, Don Beal Unix

[Ethereal-users] Capture Microsoft instant messages

2003-12-04 Thread Phillip McGroin
We are only able to view the incoming conversation side of a Microsoft messenger capture. Any suggestions on how to capture the outgoing messages? Your help with this is appreciated. _ See when your friends are online with MSN

[Ethereal-users] Capturing localhost/localhost traffic on Windows 2000

2003-12-04 Thread Martin Cooper
I just installed Ethereal on Win2K after hearing lots of good things about it. It works fine for local/elsewhere traffic and vice versa. However, if I'm running a web server on my machine and using a browser on the same machine to connect to it, nothing appears to be captured. How can I configure

[Ethereal-users] Sniffing HTTP and HTTPS requests

2003-12-04 Thread Robert Casto
I am trying to sniff HTTP and HTTPS request so I know what page is requested. The reason for doing this is that the web server is too busy to log the requests itself. The performance goes way down when logging is turned on. I can get the HTTP packets and see the headers and find out what page

Re: [Ethereal-users] Problem

2003-12-04 Thread Guy Harris
On Thu, Nov 07, 2002 at 06:02:02PM -0500, Oleg Zolotykh wrote: I have encounter a problem while using Ethereal Network Analyzer. It deals with long values of the attributes in LDAP protocol. The values which are longer than approximately 150 characters are not displayed. I'd like to know if

RE: [Ethereal-users] RFMON question

2003-12-04 Thread darren
Hi, I googled for Solomon Peachy's post and found a few in the tcpdump-workers' mail about adding support for 802.11 extended frames. However, are these just proposals or are they already implemented in the latest version of LibPcap/TCPDump/Ethereal?? I will definitely want to use his if they

Re: [Ethereal-users] Injecting a packet.

2003-12-04 Thread Jon Baer
hmm not sure how injecting a wifi packet will give you a scheme to detect malicious packets but i think what you want to do is something like airjack: http://802.11ninja.net/ http://www.michiganwireless.org/tools/Airjack/ if you want to detect malicious use kismet or network chemistry's neutrino

[Ethereal-users] RE: rtp statistics--how is delay calculated?

2003-12-04 Thread Miha Jemec
Hi! Answering the above question (I forgot there is also ethereal-users not only ethereal-dev, that is why it took so long): about delay and jitter calculation in rtp_analysis.c (or before in tap_rtp.c). delay - this is delay between two consecutive packets (this is the only information you

[Ethereal-users] (no subject)

2003-12-04 Thread Stanislav Valasek
Hi All, Does any of you has problem with interface for capture under W2K? Trying to get answer from archives but not sucessfull. In Capture - Start in combo box Interfaces - no Ifaces are listed - only : probably as a default value is present. In documentation stated that this list is updated

Re: [Ethereal-users] Ethereal on RH9

2003-12-04 Thread Guy Harris
On Thursday, July 17, 2003, at 2:50 PM, Robert Denton wrote: Does anyone know if ethereal is supposed to be stable on RedHat 9? I have just installed and updated it and it seems to crash after just a few seconds of capture pretty consistently. This doesn't necessarily have anything to do with

Re: [Ethereal-users] Building on OS X

2003-12-04 Thread Kevin
On Wednesday, August 20, 2003, at 02:51 PM, Guy Harris wrote: The attached text file is the output of configure and make. A significant difference between your configure output in mine is: Mine: checking whether GLib supports loadable modules... no Yours: checking whether GLib supports

Re: [Ethereal-users] first time

2003-12-04 Thread Chris Waters
What sort of statistics are you looking for? Regards, Chris. - Original Message - From: Rodrigo Buarque Ramos [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Thursday, November 14, 2002 3:36 AM Subject: [Ethereal-users] first time Hi! I was talking to a friend of mine and he

RE: [Ethereal-users] writing C++ dissectors

2003-12-04 Thread Kolev, Nik
Hi: Thanks for pointing out the code - it will be very helpful for my task. I also checked out the README. It says that this version of the plugin only works on a WIN32 platform. Can you recall why you could not built on Linux. Thanks again, Nik -Original Message- From: Andreas Sikkema

Re: [Ethereal-users] Re: How to get this to work

2003-12-04 Thread Andrew Swimmer
On Sep 26, 2003, at 7:30 AM, Andrew Swimmer wrote: Hi, i don't know how to get this started, i downloaded an exe, What .exe did you download? I don't know what it was called, in fact i can't find it! but it won't run for me! What does it do instead of running? I.e., presumably it

Re: [Ethereal-users] Follow this SCTP Association

2003-12-04 Thread S. Faizi
Hi Michael, Thanks! I look forward to your SCTP addition. BTW, I use ethreal a lot to capture SCTP. Good job! Best Regards, Sal - Original Message - From: Michael Tuexen [EMAIL PROTECTED] To: S. Faizi [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Sent: Thursday, March 20, 2003 1:19 PM

[Ethereal-users] Snooping ethernet

2003-12-04 Thread Mike Stickney
I've encountered a problem with a hardware vendor that has created their own transmission control protocol. During a hardware test on 3 June 2003 they were using standard TCP packets and I was able to capture and analyze them using ethereal. In a subsequent test on 11 July 2003 ethereal was

RE: [Ethereal-users] Sniff wireless on the same machine?

2003-12-04 Thread Jeff Threlfall
I ran into this myself a while back, but traces from a 3rd station showed that packets were being encrypted on the WEP enabled station. One thing to note about XP's handling of Wireless adapters: You probably shouldn't use the raw configuration properties of the adapter. If you use the simple GUI

Re: [Ethereal-users] New User - Only Seeing LLC Packets?!?

2003-12-04 Thread Guy Harris
On Mon, Jan 20, 2003 at 03:04:48PM -0800, arh wrote: Thanks for the suggestion. Forget NmapNT -- there is now a Win32 version -- still in Alpha (3.10ALPHA7-win32) of Nmap itself, Actually, the Win32 port of nmap may just be the result of the eEye people giving their changes from NmapNT back to

[Ethereal-users] how does ethereal determine whether RTP or not?

2003-12-04 Thread darren
Hi all, I did some capture of a Video stream with ethereal on my own computer...after which ethereal correctly identified the UDP packets as being RTP. After I did a filter on all the RTP packets (filter RTP) and save the filtered packets in a separate file, I reopened the file in another

[Ethereal-users] Ethereal and SafeNet Secure VPN Client

2003-12-04 Thread Martin Cooper
After installing Ethereal on Windows 2000, I now find that I can no longer connect to my company's intranet using SafeNet Secure VPN Client. (This is without Ethereal itself running at the same time.) What do I need to do to get the VPN client working again? Thanks! -- Martin Cooper

Re: [Ethereal-users] editing tcpdumpcapture files

2003-12-04 Thread Martin Regner
Where can I find the file format for tcpdump capture files? I need to edit some data. The best is maybe to look on the source code. You'll find the code that handles lipcap files in /wiretap/libpcap.c and /wiretap/libpcap.h There is a summary of libpcap format on the following web-page:

[Ethereal-users] packet injector

2003-12-04 Thread erythros
does anyone have a sugestion as to the best packet injector to use with ethereal?this message broken by erythros.com

Re: [Ethereal-users] Re; Advise on installing on MS Windows

2003-12-04 Thread Guy Harris
On Nov 6, 2003, at 3:11 PM, [EMAIL PROTECTED] wrote: Please advise us if Etherreal can be installed on MS Windows various version, particularly XP or Windows 2000. http://www.ethereal.com/download.html and search on that page for Windows. Also do you have specific instruction set/requsites for

[Ethereal-users] tethereal packet-length in real-time

2003-12-04 Thread D. G
hi all, is it possible to obtain packet-lengthsin real time using tethereal? any help and / or suggestions, much apreciated. thanks, graithSTOP MORE SPAM with the new MSN 8 and get 2 months FREE*

[Ethereal-users] Gnutella capture filter

2003-12-04 Thread Matt Bailey
I'm trying to set up a filter so I only capture Gnutella packets that contain a search string. I can set up a display filter that finds the correct packets (gnutella.header.payload==128) but would like to filter at capture because of the large volumes involved. Does anyone know how I can do

[Ethereal-users] Save or export of Color filters for Windows version

2003-12-04 Thread Kevin Hulse
Title: Save or export of Color filters for Windows version Where are the color filters stored for the Windows version ? Is it possible to save these filters so that they can be sent to another Ethereal user and be used along with a capture ? Thanks in advance, Kevin

Re: [Ethereal-users] Payload of TPKT is missing

2003-12-04 Thread Guy Harris
On Mon, Oct 06, 2003 at 10:49:32AM +0800, #YANG YONG# wrote: When I captured a TPKT packet, ethereal said it contained a Q.931 message, and the length was 200. But in fact ethereal captured nothing of the payload of the TPKT packet. The record is attached for your information. I wonder why.

[Ethereal-users] Help!

2003-12-04 Thread nancyd
I have downloaded and installed ethereal 0.9.10 to use on our ethernet network using NT4.0. I also installed winpcap. When I try to start a capture, I get the following error message. Can you please tell me what I am missing? I am not sure what I should specify the interface as. (Embedded

Re: [Ethereal-users] ethereal crashes while loadin the captured file.

2003-12-04 Thread Martin Regner
Ravi Mudium wrote: I have 90 Mb capture file. When I try to stop the capture ethereal crashed while loading the capture file. Error message it gave is GLib-ERROR **:could not allocate 65536 bytes. It might be some problem with MAPI and/or DCE-RPC dissectors in Ethereal 0.9.12 (and at least

[Ethereal-users] Ethereal 0.9.7 (Win32) sudden exit

2003-12-04 Thread Kirk Schafer
Hello, Thanks for developing and supporting this product. While capturing packets with Win32 Ethereal 0.9.7, I started to experience sudden crashes (lots of disk activity immediately before the program vanishes), usually when stopping a promiscuous mode capture. My system is P4-1.8GHz

Re: [Ethereal-users] Problem with W2K Installation - follow up

2003-12-04 Thread Gerald Combs
On Thu, 10 Apr 2003, Guy Harris wrote: As the Windows version of Ethereal is bundled with its own version of the SNMP library, perhaps it should *always* use its own directory. The SNMP dissector includes code that, on Win32, forcibly sets the MIBDIRS environment variable to point to its

[Ethereal-users] I captured nothing, help.

2003-12-04 Thread Gang Peng
I checked the user's guide,downloaded and installed the WinPcap 3.0 alpha 4 and ethereal-setup-0.9.8.exe at http://www.ethereal.com/distribution/win32/and http://winpcap.mirror.ethereal.com/install/default.htm; then whe I run it, I didn't capture anything and top packet list pane shows

[Ethereal-users] 2 Win2k Systems

2003-12-04 Thread bjost
Benedikt Jost Univerisity of Applied Science Koblenz, Germany Hi! Is it possible to run Ethereal on a system with two Win2k partitions? It seems that it is not possible to run E. on the second partition. We have a working version of E. on the first partition. If we boot the first p., everything

[Ethereal-users] How to display traffic ??

2003-12-04 Thread JoanBa .
Hi, Sorry for my previous garbage... webmail is not so well configured... I've installed Ethereal vers. 0.9.11 with WinPCap 2.3. When I try to trace a telnet session for example, I only can see one side of the conversation, for example, from my computer, 172.16.8.147 to the server

Re: [Ethereal-users] (no subject)

2003-12-04 Thread Guy Harris
On Tue, Apr 22, 2003 at 09:56:42AM -0400, [EMAIL PROTECTED] wrote: Below is a screenshot that I get when I display a capture. I am trying to locate an issue during the timeframe of this capture and the capture displays fine, however, I get this every time I open it. This may be the smoking

Re: [Ethereal-users] finding iSCSI PDUs

2003-12-04 Thread Martin Regner
Eddy Quicksall wrote: It is sometimes hard to find all iSCSI PDU headers with Ethereal. The reason is that some captured lines will contain several headers but only the first header is displayed. Given that, I would like to write a program to extract all packets for port 3260 and pick out all PDU

Re: [Ethereal-users] Trying... My first email.

2003-12-04 Thread Ronnie Sahlberg
Yes, Ethereal will decode Voice over IP, or H.323 but you must use the latest version 0.9.15 in order to use ethereal with h.323. Download the RTP example capture from the ethereal web site and test. That example capture contains voip traffic. - Original Message - From: Sakri Ahmad

RE: [Ethereal-users] Terrible capture rates

2003-12-04 Thread BUYCK Jacky FTRD/DMI/CAE
Hi. This is really interesting ! Have youmake the same test using tcpdump -w ??? It could be a good thing to compare both. JB. -Message d'origine- De : Ian Schorr [mailto:[EMAIL PROTECTED] Envoyé : jeudi 13 mars 2003 10:50 À : [EMAIL PROTECTED] Objet :

RE: [Ethereal-users] Mac filtering

2003-12-04 Thread Nicoson Dave
Title: RE: [Ethereal-users] Mac filtering After selecting capture, put this in the filter field: ether host MAC address e.g., ether host 00:10:95:78:1C:F0 http://www.ethereal.com/docs/user-guide/ch03capfilt.html#CH03EXFILT1 -Original Message- From: Kevin Kobe [mailto:[EMAIL

Re: [Ethereal-users] capturing cisco ata186 traffic

2003-12-04 Thread Guy Harris
On Oct 8, 2003, at 6:25 AM, Mat Ford wrote: I'm trying to us ethereal to capture traffic from my Cisco ATA186 VoIP adapter but ethereal seems unable to see any of the traffic. Is Ethereal running on a machine to which all of the traffic is going, or is some of it traffic going neither to nor

Re: [Ethereal-users] Capturing on a dial up line

2003-12-04 Thread Martin Regner
Martin Regner wrote: Besides the information in FAQ 5.12 (http://www.ethereal.com/faq.html#q5.12) I can mention that there **might** be a work-around on Windows 2000 by installing Network Monitor driver as described on the following page: http://winpcap.polito.it/misc/dialup.htm After you have

[Ethereal-users] Ethereal and PDA

2003-12-04 Thread BUYCK Jacky FTRD/DMI/CAE
Hi all. Yes I think that I'll ask a really strange question but ... ;) I plan to buy an iPaq because it can really be could and also because I can get it half of the price. I want to used it in my job of course (network security) and I wonder two things : - is there an

[Ethereal-users] Display filter question!!

2003-12-04 Thread Mathias Björkander TACMa
Hi All. Is there any way of setting up a display filter and/or a capture filter that trigs at SSL packages that includes more then one Record Layer? Best regards Mathias ***Ethereal rules!!!***

[Ethereal-users] OT: how to duplicate traffic for ethereal?

2003-12-04 Thread darren
Hi all, this is slightly off topic, but i was hoping some of you may have done it before. I have a Linux Box doing simple IPv4 routing from 1 NIC to 2 NICs. I would like to place my ethereal machine on the second nic to sniff only ports 23 and 80, but route ALL (including 23 and 80) to the

Re: [Ethereal-users] finding iSCSI PDUs

2003-12-04 Thread Martin Regner
Eddy Quicksall: Perhaps there is a simple way to use some of the Ethereal tools to just extract the data as a stream of bytes for a particular TCP port. That would be all I need. If you just want to dump all the octets for a certain TCP stream (one or both directions) then you have the Follow

[Ethereal-users] Question

2003-12-04 Thread FRANCIS FERRER

Re: Re: [Ethereal-users] Effort to implement support for a new protocol

2003-12-04 Thread Daniel Scheibli
Hi Andy, Hi Guy, thank you very much for the provided insights. I will download the source and give it a try. CU Daniel

Re: [Ethereal-users] Colorize Display

2003-12-04 Thread Martin Regner
Griffin Canak wrote: Can someone tell me where Ethereal - Windows Version - stores the Colorize Display options? I have set up Ethereal colors on one computer and would like to transfer these colors to another computer. There is a file colorfilters where color filters are stored (if you have

[Ethereal-users] Ethereal-users Digest, Vol 2, Issue 51

2003-12-04 Thread mark.peart
I'll be out of the office until 30th June.

Re: [Ethereal-users] Packet blocking with Ethereal

2003-12-04 Thread Richard Urwin
On Saturday 18 Oct 2003 7:05 am, NJR Srinivas wrote: Hello , I am developing packet blocking utility on windows(2000 and XP). Is ethereal helpful for me? How do we block the packet using ethereal. You don't. Ethereal doesn't affect the packets in any way. You could use it when you are

Re: [Ethereal-users] OT: How does ethereal/libpcap determine the layer 3 type?

2003-12-04 Thread Guy Harris
On Wed, Sep 03, 2003 at 03:45:37AM +, darren wrote: I am wondering how the libpcap engine determine the type of layer 3 (issit IP or IPX...blah blah) protocol during a capture. The libpcap code doesn't do that itself. The BPF program it, or the BPF interpreter in kernel mode, is

Re: [Ethereal-users] ethereal 0.9.11 on RedHat 8.0 with net-snmp fails on -lelf

2003-12-04 Thread Joerg Mayer
On Sun, Mar 16, 2003 at 07:39:39PM -0500, James R. Hendrick wrote: it builds all the .o files, but the link fails on ld -lelf... linking ehtereal. Can you please log the error and send the complete linker command and the following (error) messages to this list? Thanks Jörg -- Joerg

[Ethereal-users] How I can convert captured file to ASCII format?

2003-12-04 Thread Dangis
Hello, How I can convert captured file with Ethereal to ASCII format? Thanks!

Re: [Ethereal-users] Text search/etc

2003-12-04 Thread Guy Harris
On Wed, Mar 26, 2003 at 04:25:10PM -0500, Ian Schorr wrote: Is it possible for me to build a filter/search on a particular string that may occur anywhere inside the packet view or tree view? http://www.ethereal.com/faq.html#q5.29 Also, along exact opposite lines, is there a way to

<    1   2   3   4   5   6   7   8   9   10   >