Re: [Wireshark-users] Wireless recommendation

2007-03-19 Thread David Schweinsberg
Thanks Andreas I've installed your build on my MacBook Pro and I'm seeing local traffic on 'en1', and broadcasts on 'wlt1', but no other network else. The config for en1 is set to promiscuous, and checking 'ifconfig en1' reveals that the PROMISC flag is set -- it just doesn't seem to mak

Re: [Wireshark-users] Wireless recommendation

2007-03-19 Thread Andreas Fink
the wireless issue on the MacBook Pro have been solved You need an updated libpcap version. the installer I put at http://www.finkconsulting.com/page7 has this fix. On 20.03.2007, at 05:30, David Schweinsberg wrote: Hi I was hoping for a recommendation for the best wireless card to use w

[Wireshark-users] Wireless recommendation

2007-03-19 Thread David Schweinsberg
Hi I was hoping for a recommendation for the best wireless card to use with Wireshark on Linux. I've looked through the various cards and chipsets on the wireless wiki section, but there seems to be so clear consensus as to which is the best option. Alternatively, I have a MacBookPro which

Re: [Wireshark-users] How to know how much data transferred

2007-03-19 Thread Luis Ontanon
For that kind of use you probably prefer ntop over wireshark. http://www.ntop.org On 3/19/07, Abhishek Chavan <[EMAIL PROTECTED]> wrote: > > any format where the data can be seen stored and like i leave wireshark to > capture at night and come the next day to see the data to actually know > amount

Re: [Wireshark-users] Dissecting RouterOS 802.11 capture files.

2007-03-19 Thread Guy Harris
On Mar 19, 2007, at 11:52 AM, Guy Harris wrote: > Another possibility would be a libpcap-based program to read a > RouterOS > capture and write out a valid radiotap capture, adding the padding to > the RouterOS radiotap header. ...which would let *any* program that handles valid radiotap heade

Re: [Wireshark-users] How to know how much data transferred

2007-03-19 Thread Abhishek Chavan
any format where the data can be seen stored and like i leave wireshark to capture at night and come the next day to see the data to actually know amount of data transferred ___ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wiresh

Re: [Wireshark-users] Dissecting RouterOS 802.11 capture files.

2007-03-19 Thread Guy Harris
Guy Harris wrote: > I have no interest in breaking the radiotap dissector by making it > assume no padding. If there's a *reliable* mechanism for detecting > RouterOS's broken radiotap header, I'd be willing to accept a patch from > somebody for that, but I don't want to lose any ability to re

Re: [Wireshark-users] How to know how much data transferred

2007-03-19 Thread Stephen Fisher
On Mon, Mar 19, 2007 at 12:27:17PM +0530, Abhishek Chavan wrote: > ya it can be seen in tht but i need to show in a proper format any > idea?? What format do you need? Steve ___ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.w

Re: [Wireshark-users] Dissecting RouterOS 802.11 capture files.

2007-03-19 Thread Guy Harris
Sten Daniel Soersdal wrote: > Hi, i'm a new Wireshark user, old time Ethereal user. Same program, just a different name. > I noticed Wireshark cannot read properly the capture files captured by > routeros (www.mikrotik.com). Either that, or RouterOS isn't properly *writing* the capture files. >

[Wireshark-users] Dissecting RouterOS 802.11 capture files.

2007-03-19 Thread Sten Daniel Soersdal
Hi, i'm a new Wireshark user, old time Ethereal user. I noticed Wireshark cannot read properly the capture files captured by routeros (www.mikrotik.com). It is only the 'radiotap header' that displays incorrectly. The packets' radiotap header shows: Header revision: 0 Header pad: 0 Header lenght: