[Wireshark-dev] Wireshark 2.4.1 is now available

2017-08-29 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.4.1. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education.

[Wireshark-announce] Wireshark 2.4.1 is now available

2017-08-29 Thread Wireshark announcements
I'm proud to announce the release of Wireshark 2.4.1. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education.

Re: [Wireshark-dev] Adding pcap-ng pipe support to dumpcap

2017-08-29 Thread Richard Sharpe
On Tue, Aug 29, 2017 at 10:50 AM, Ed Beroset wrote: > On 06/16/2017 01:27 PM, Richard Sharpe wrote: >> >> On Fri, Jun 16, 2017 at 9:36 AM, Kvidera, Evan D >> wrote: >>> >>> Hello Wireshark Devs, >>> >>> My name is Evan Kvidera and I am a senior

[Wireshark-dev] Wireshark 2.2.9 is now available

2017-08-29 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.2.9. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education.

[Wireshark-announce] Wireshark 2.2.9 is now available

2017-08-29 Thread Wireshark announcements
I'm proud to announce the release of Wireshark 2.2.9. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education.

Re: [Wireshark-dev] Adding pcap-ng pipe support to dumpcap

2017-08-29 Thread Ed Beroset
On 06/16/2017 01:27 PM, Richard Sharpe wrote: On Fri, Jun 16, 2017 at 9:36 AM, Kvidera, Evan D wrote: Hello Wireshark Devs, My name is Evan Kvidera and I am a senior undergraduate student studying Computer Science. I have a decent amount of programming experience, but

Re: [Wireshark-dev] [RFC] Vendor-specific dissector extension for EtherNet/IP

2017-08-29 Thread Michael Mann via Wireshark-dev
The answer depends on exactly what you are trying to do, some things will be easier than others. 1. If you want to add vendor specific objects, that can easily be done in Lua because there is a dissector table that you can just register your vendor specific class with ("cip.class.iface").

Re: [Wireshark-dev] Adding pcap-ng pipe support to dumpcap

2017-08-29 Thread Ed Beroset
On 08/29/2017 02:35 PM, Richard Sharpe wrote: On Tue, Aug 29, 2017 at 10:50 AM, Ed Beroset wrote: On 06/16/2017 01:27 PM, Richard Sharpe wrote: I've just encountered a need for this as well. Have you made progress, Evan? Do you want some help? Evan seems to have

Re: [Wireshark-dev] External processes in Snort dissector - code execution

2017-08-29 Thread Jakub Zawadzki
Hi Peter, W dniu 2017-08-28 18:50, Peter Wu napisał(a): This can especially problematic for services like Cloudshark and Webshark (by Jakub). The former is not yet affected since it does not use 2.4 code (yet?) but the latter seems theoretically vulnerable as it has a setconf API function (I

Re: [Wireshark-dev] External processes in Snort dissector - code execution

2017-08-29 Thread Peter Wu
On Tue, Aug 29, 2017 at 10:13:04AM +0200, Jakub Zawadzki wrote: > Hi Peter, > > W dniu 2017-08-28 18:50, Peter Wu napisał(a): > > This can especially problematic for services like Cloudshark and > > Webshark (by Jakub). The former is not yet affected since it does not > > use 2.4 code (yet?) but

[Wireshark-dev] [RFC] Vendor-specific dissector extension for EtherNet/IP

2017-08-29 Thread Samuel Groot
Hi, I am considering writing a chained dissector in lua to support some vendor-specific classes, services and attributes for EtherNet/IP. After digging around on google or ask.wireshark.org, I couldn't find anything that would fit my needs (except this[1], but it's more than 10 years old),

[Wireshark-dev] Idea about Adding extra functionality in wireshark.

2017-08-29 Thread krishna Kulkarni
Sir My research paper related to identifying DOS and DDOS attack.research paper parameter is Tx power rate.Now I want to add this functionality into wireshrak so the software also identify the attacks defaultly.I want your team guidance so we develop a better concept in wireshark. we can