[Wireshark-dev] unsubscribe not working

2008-05-31 Thread Bill Fassler
I decided to unsubscribe while I was on vacation. I received a confirmation email, but I am still receiving emails from wireshark-dev Bill ___ Wireshark-dev mailing list Wireshark-dev@wireshark.org

Re: [Wireshark-dev] ethernet over USB

2008-02-01 Thread Bill Fassler
, the USB Forum specifications might be of use. Hope that helps. On Jan 31, 2008 10:57 PM, Bill Fassler [EMAIL PROTECTED] wrote: Hey guys, I have been trying to understand ethernet over USB. I have ethernet over USB working on an embedded development board running a blackfin DSP and uClinux

Re: [Wireshark-dev] ethernet over USB

2008-02-01 Thread Bill Fassler
00 00 00 00 00 00 ec 56 00 muV. 0010 00 00 00 00 08 00 00 00 08 00 00 00 00 00 00 00 0020 ca a6 50 00 c8 eb 56 00 c4 eb 56 00 40 51 51 00 [EMAIL PROTECTED] 0030 03 00 00 00 03 00 00 00 Bill Fassler [EMAIL PROTECTED] wrote

[Wireshark-dev] ethernet over USB

2008-01-31 Thread Bill Fassler
better? I am thinking about writing a non-linux based version of this.. and don't understand it enough to even start just yet.. Bill Fassler - Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now

[Wireshark-dev] hpna 3.0

2008-01-24 Thread Bill Fassler
Hey guys, I haven't done any Wireshark plugins or anything in quite a while, but am still part of the mailing list... Someone just asked me if Wireshark sniffs HPNA 3.0 and I wasn't sure. Does it, if so what version do I need to upgrade to? I am currently running 99.5 I think Bill

Re: [Wireshark-dev] dissector for OpenVPN

2007-04-03 Thread Bill Fassler
I understand. I think there is more than one person with a strong interest in this and I am certainly willing to help since it will provide me with additional debug capability. Bill Guy Harris [EMAIL PROTECTED] wrote: On Apr 2, 2007, at 2:27 PM, Bill Fassler wrote: I opened a bug

[Wireshark-dev] dissecting and decoding an 8 byte field

2007-03-26 Thread Bill Fassler
Is there recommended way to decode 8 byte fields? I see I can use FT_NONE with a size of 8 bytes and the appropriate bytes highlight in the bytes of the packet, but the value does not display in the decoded details? Bill - No need to miss a message. Get email

[Wireshark-dev] My postings are getting lost

2007-03-22 Thread Bill Fassler
I have repeatedly tried to post a response to Joerg Mayer regarding decoding traffic thru OpenVPN. Although I provided a one packet sample, Joerg requested a small capture of traffic, so when I attach a small capture the email is about 1Mb and gets bounced. Is there any way to get around

Re: [Wireshark-dev] decoding thru unencrypted VPN tunnel

2007-03-16 Thread Bill Fassler
be done is to make a dissector for OpenVPN packages a protocol description Of sorts can be found at http://svn.openvpn.net/projects/openvpn/trunk/openvpn/ssl.h Best regards Anders Från: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] För Bill Fassler Skickat: den

[Wireshark-dev] decoding thru unencrypted VPN tunnel

2007-03-13 Thread Bill Fassler
My last post on this subject wound up on the wrong forum, so I'd like to repost here. My traffic is encapsulated in a VPN tunnel, when it is unencrypted I can see the start of the IP protocol 5 bytes into the payload. The first 5 bytes are overhead protocols for the tunnel itself (some form of

Re: [Wireshark-dev] decoding thru unencrypted VPN tunnel

2007-03-13 Thread Bill Fassler
..~}{|}}}~}~...~ 00c0 fe fd fe 7e 7c 7b 7f fc fa fc fd fb fa...~|{... Stephen Fisher [EMAIL PROTECTED] wrote: On Tue, Mar 13, 2007 at 10:47:44AM -0700, Bill Fassler wrote: My traffic is encapsulated in a VPN tunnel, when it is unencrypted I can see the start of the IP

[Wireshark-dev] dissector/decoder and value strings

2007-02-28 Thread Bill Fassler
I was just modifying a dissector plugin that I wrote a few months back and am having some problems where I least expected them. Since this is similar to what I already have working I am perplexed. Here is a value string that is not printing out in the dissection. Can anyone see a reason? 1)

[Wireshark-dev] decoding thru a VPN tunnel

2007-02-28 Thread Bill Fassler
I started a thread on this a while back. I see now that with 0.99.5 I can now use decode as with more choices including IP. That puts me VERY close to being able to dissect our software going through the VPN tunnel (when it is not encrypted I.E. when I use a NULL encryption key). The only

Re: [Wireshark-dev] Small (but annoying) display issue

2006-10-24 Thread Bill Fassler
"vppn.led.timing3", FT_UINT16, BASE_DEC, VALS(blink_vals), SLOT_3, "3rd second", HFILL }},and a proto_tree_add_item(... hf_led_timing_3, ...); On 10/24/06, Bill Fassler [EMAIL PROTECTED] wrote: You haven't heard from me for a while because with everyones help I progressed from com

[Wireshark-dev] Small (but annoying) display issue

2006-10-23 Thread Bill Fassler
ON for .5s and OFF for .5s 0010 = LED Timing slot 3: Blink at: 0010 = LED Timing slot 4: Blink at: 0010 = LED Timing slot 5: Blink at: 0010 = LED Timing slot 6: Blink at: I apologize for such a petty question, but its drivin' me nuts.

[Wireshark-dev] Preventing the display of the payload data in the proto tree

2006-09-22 Thread Bill Fassler
a sub_tvb from the current offset to the end of the frame (assumingthe data is at the end) and hand that to the data dissector. Lots ofsamples in other dissectors.Thanx,JaapOn Thu, 21 Sep 2006, Bill Fassler wrote: Ya know how the first branch of the plugin tree highlights the entire packet, the header

[Wireshark-dev] Is it possible to add the actual data (80 bytes) to the proto tree in a chunk?

2006-09-21 Thread Bill Fassler
Ya know how the first branch of the plugin tree highlights the entire packet, the header, data and everything? Well, my superiors (who is everybody in the world it seems) insist that I add a final branch that highlights the actual data packet (in this case - an 80 byte audio packet). Everything I

[Wireshark-dev] Ethereal 0.10.11 vs WireShark 0.99.3

2006-09-21 Thread Bill Fassler
Now that the test and debug team are using my plugin they had to switch from Ethereal to Wireshark and they are complaining because Ethereal seems to remember (saves) the settings and preferences for capture options and they all have to reset them manually every time they launch Wireshark.Why

Re: [Wireshark-dev] WireShark crashes when I try to use a filter on my plugin dissector

2006-09-20 Thread Bill Fassler
concern now is that the first and last entries are zero. Could this create any run time problems?{0x00, "No Operation"}...{0, NULL}Gilbert Ramirez [EMAIL PROTECTED] wrote: On 9/19/06, Bill Fassler <[EMAIL PROTECTED]> wrote: Thanks Guy, Jaap et al for helping me through this. My plugin

[Wireshark-dev] plugin proprietary dissector for Wireshark 0.99.3

2006-09-19 Thread Bill Fassler
I could use a little more help. The propietary protocol I am working with has a one byte ID at the ends of both the source and destination MAC addresses. This Source (SID) or Destination (DID) ID helps me identify whether the packet was generated by a Master board or a slave board and also helps

[Wireshark-dev] WireShark crashes when I try to use a filter on my plugin dissector

2006-09-19 Thread Bill Fassler
IL PROTECTED] wrote: Hi,Better use:proto_tree_add uint(vppn_tree, hf_dest_id, tvb, 0, 0, packet_info.dl_dst);Thanx,JaapOn Mon, 18 Sep 2006, Bill Fassler wrote: I could use a little more help. The propietary protocol I am working with has a one byte ID at the ends of both the source and destination MA

[Wireshark-dev] plug in dissector for Wireshark 0.99.3

2006-09-15 Thread Bill Fassler
I am working on a proprietary VoIP protocol plugin. I have my build enviornment configured and am apparently producing a usable plugin dll. My company isolates its intenal development machines from the external Internet, so what I wind up doing is building on a Internet capable workstation in

Re: [Wireshark-dev] plug in dissector for Wireshark 0.99.3

2006-09-15 Thread Bill Fassler
is fairly easy to work with and I made good progress in the last few days for not having any idea how to do it before Monday. With help from pros like you I should have this plugin spit and polished in no time.Thanks again,BillGuy Harris [EMAIL PROTECTED] wrote: On Sep 15, 2006, at 12:14 PM, Bill