Re: [Wireshark-users] Symantec claims there is a trojan

2006-07-03 Thread Gerald Combs
Oleg wrote: > Just wanted to inform that newest SAVC 10.1 definitions (07.01) are > claiming there is a Trojan.Zlob in windows installer (from sf.net). I > know it's a false (a lot of problems with SAVC defs lately), just > wanted to inform. Anyone with 0.99.1pre1 installed is advised to check

Re: [Wireshark-users] Symantec claims there is a trojan

2006-07-03 Thread Gerald Combs
Symantec hasn't been very helpful so far. They keep telling me to "run a full system scan to remove the trojan." Gerald Combs wrote: > Oleg wrote: >> Just wanted to inform that newest SAVC 10.1 definitions (07.01) are >> claiming there is a Trojan.Zlob in wind

Re: [Wireshark-users] Trojan.Zlob detected in Windows installer

2006-07-04 Thread Gerald Combs
Joerg Mayer wrote: > On Mon, Jul 03, 2006 at 09:48:28AM +1200, Allen Unueco wrote: >> This morning Symantec Antivirus had reported that >> 'wireshark-setup-0.99.1pre1.exe' contained Trojan.Zlob. > > Can you please report this to Symantec, so they can fix their > signatures? Some virus vendors need

[Wireshark-users] Wireshark 0.99.2pre1 is available

2006-07-10 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.2pre1 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.2pre1.tar.gz http://www.wireshark.org/download/prerelease/wireshark-

Re: [Wireshark-users] Problem Compiling 0.99.2pre

2006-07-31 Thread Gerald Combs
The output below doesn't indicate any errors. When you ran "configure", what was printed at the end? Specifically, did it print the line Build wireshark : yes Also, is TShark being built? TimothyR wrote: > I'm resending this since I've gotten no response from > multiple sources. Hopefully

Re: [Wireshark-users] Problem Compiling 0.99.2pre

2006-07-31 Thread Gerald Combs
no > Use GNU crypto library : no > Use SSL crypto library : no > Use IPv6 name resolution : yes > Use UCD SNMP/Net-SNMP library : no > Use gnutls library : no > > --- Gerald Combs <[EMAIL PROTECTED]> wrote: > >>

Re: [Wireshark-users] Roadmap question

2006-08-14 Thread Gerald Combs
Joerg Mayer wrote: > On Mon, Aug 07, 2006 at 10:21:34AM +0200, Jaap Keuter wrote: >> If you could help along with bugs 396 and 699 that would help a lot >> getting the pending items for 0.99.3 done, see >> http://wiki.wireshark.org/Development/Roadmap. > > Hmm, I'm missing the capture separation i

Re: [Wireshark-users] Why is default filter 'not tcp port 3389' ?

2006-08-27 Thread Gerald Combs
Andrew Schweitzer wrote: > Jee Kay wrote: >> On 26/08/06, Ben Stover <[EMAIL PROTECTED]> wrote: >> >>> After the installation of WireShark the default Capture filter is set to >>> 'not tcp port 3389' >>> Why ? >> >> Because you're connecting to the machine via RDP. > > I always wondered that mysel

Re: [Wireshark-users] Version not limited by United States export controls?

2006-09-10 Thread Gerald Combs
Andrew Hood wrote: > Anothony Georgeo wrote: >> Hi, >> >> I read v.0.99.3 is now under the US export control due >> to it's decryption features. What limits do the US >> export contorls put on this new version? > > It means it can not be exported to countries to which you can not export > encryp

[Wireshark-users] Barracuda false positive?

2006-10-03 Thread Gerald Combs
I received a message from a user that the Barracuda spam/virus firewall has detected the ILookup.Sbus worm in the Wireshark 0.99.2 release. This appears to a false positive -- the worm comes in a file named "sbus.dll", which is the same name used by Wireshark's S-Bus plugin. Are there any Barracud

Re: [Wireshark-users] using ssl filter for ssh trafic?

2006-10-05 Thread Gerald Combs
Along with support for the SSL/TLS protocols, OpenSSL has a rich cryptographic library. As far as I know, OpenSSH makes use of the crypto bits in OpenSSL, but not the SSL/TLS bits. Jeff Sadowski wrote: > Why is it then on every linux install that openssl is a dependancy for > ssh ssh must be usin

Re: [Wireshark-users] Lost packets can not ping my machineonmynetwork

2006-10-13 Thread Gerald Combs
You might try verifying your Windows firewall settings by running "netsh firewall show config" and "netsh firewall show state" from the command line. Microsoft has a KB article on firewall troubleshooting at http://support.microsoft.com/kb/875357 . David Ackie wrote: > Well I suppose reinstalling

[Wireshark-users] Wireshark 0.99.4pre1 is now available

2006-10-21 Thread Gerald Combs
Wireshark 0.99.4pre1 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.4pre1.tar.gz http://www.wireshark.org/download/prerelease/wireshark-setup-0.99.4pre1.exe The wireshark.org mirrors

Re: [Wireshark-users] 3rd time Posting -- Please help Regarding SSL decryption with tshark

2006-10-25 Thread Gerald Combs
Vijay Sitaram wrote: > Hi, > >I am not sure if this has been attempted before, but would really > appreciate some help / guidance. We are trying to decrypt SSL > application data by using 'tshark' on RedHat Linux using the following > command: > tshark -V -r rsasnakeoil2.cap -R > "127.0.0.1,

[Wireshark-users] Wireshark 0.99.4pre2 is now available

2006-10-30 Thread Gerald Combs
Wireshark 0.99.4pre2 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.4pre2.tar.gz http://www.wireshark.org/download/prerelease/wireshark-setup-0.99.4pre2.exe The wireshark.org mirrors

Re: [Wireshark-users] bug info

2006-11-19 Thread Gerald Combs
BEA wrote: > Can't get pathname of Wireshark: GetModuleFileName failed: 120 > (FormatMessage failed: 120). > It won't be possible to capture traffic. > Report this to the Wireshark developers. > > that what ihttp://bugs.wireshark.org/bugzilla/show_bug.cgi?id=964 __

Re: [Wireshark-users] Network Communications Network Probe 7100 on eBay - NO power supply

2006-12-08 Thread Gerald Combs
Richard Cranium wrote: > > http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=170058381224 > > > > Network Communications Network Probe 7100 I'm not sure I understand. Is this a hint that we need a per-packet pseudoheader

Re: [Wireshark-users] Yet another libcap question....

2006-12-19 Thread Gerald Combs
Chris Nighswonger wrote: > Hi all, > I've run into the proverbial pcap.h issue. I'm running FC6 and have > both libcap and libcap-devel installed via Yum. Most likely neither > included the pcap.h header file. So, my question is: Can I simply > download the libcap source and do a "make install-in

Re: [Wireshark-users] I see no captured packets at all

2006-12-29 Thread Gerald Combs
...or you could just buy one of these: http://www.cacetech.com/products/airpcap.htm (Apologies for the shameless plug.) Small, James wrote: > Cor, > > Unfortunately, many wireless cards in Windows do not allow you to do > network captures. I use to have a link to a web site that explained

Re: [Wireshark-users] Help on Protocols in frame

2007-01-09 Thread Gerald Combs
What version are you running on Solaris? You may need to upgrade to a more recent version. ARAMBULO, Norman R. wrote: > Hi, > > Im using ethereal for capturing IP packets and the platform we used is > Linux Enterprise, when we try to display the decode like on the frame it > shows the ff. > >

Re: [Wireshark-users] Help on Protocols in frame

2007-01-10 Thread Gerald Combs
ARAMBULO, Norman R. wrote: > Hi gerald, > > Well, Im running it on a Solaris9 sparc. Can I use the wireshark > instead, but I cant find a stable or an installer for Solaris9 > > Hope you can help me with this. Thanks You might try Blastwave: http://www.blastwave.org/packages.php/wireshark

[Wireshark-users] Wireshark 0.99.5pre1 is now available

2007-01-19 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.5pre1 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.5pre1.tar.gz http://www.wireshark.org/download/prerelease/wireshark-

Re: [Wireshark-users] [ANNOUNCE] WinPcap 4.0 has been released

2007-01-30 Thread Gerald Combs
Whoah there! :) I just copied WinPcap 4.0 into the 0.99.5 trunk, and plan on releasing 0.99.5pre2 later today. I'll send a message when it's ready. I'm hoping to have 0.99.5 final out on Thursday or Friday. Jaap Keuter wrote: > Hi List, > > On the back of WinPCap 4.0 our fearless leader has

[Wireshark-users] Wireshark 0.99.5pre2 is now available

2007-01-30 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.5pre2 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.5pre2.tar.gz http://www.wireshark.org/download/prerelease/wireshark-

[Wireshark-users] Wireshark 0.99.5 is now available

2007-02-02 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.5 has been released. What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development, and education. What's New Bug Fixes The following vulnerab

Re: [Wireshark-users] OUI Look Up Tool on Wireshark site?

2007-02-03 Thread Gerald Combs
Well, that _used_ to work, but it now tries to look up entries in an empty array (which is empty because the Ethereal SVN server has gone the way of the dodo). I managed to add an OUI lookup tool to the Wireshark site: http://www.wireshark.org/tools/oui-lookup.html It runs a little slow (on

Re: [Wireshark-users] R: U3 Package?

2007-02-03 Thread Gerald Combs
Ulf Lamping wrote: > Davide Schiera wrote: >> Hi Scott, >> have you tried to follow the link in the announcement >> (http://www.wireshark.org/download/) to find the link >> http://www.wireshark.org/download/win32/wireshark-0.99.5.u3p? >> > However, there's no link from the download web page to t

Re: [Wireshark-users] Questions about the latest release

2007-02-07 Thread Gerald Combs
Thomas Nyheim wrote: > Firstly, how does the WPA decryption work? If all of the following conditions are true: - You're using pre-shared keys - All 4 RSNA handshake packets are present for the session you're trying to decrypt - You've specified the proper password, password+SSID, or raw

Re: [Wireshark-users] Installation issue with Wireshark 0.99.5

2007-02-08 Thread Gerald Combs
Rob Kuiters wrote: > As I installed wireshark 0.99.5 with the winpcap 4.0 installer McAffee > noticed that the winpcap installer did put Adware-Softomate.dll on to my > system. > Installing winpcap and wireshark seperatly didn't cause this issue. The WinPcap 4.0 installer that ships with Wireshark

Re: [Wireshark-users] 0.99.5 and Adware

2007-02-10 Thread Gerald Combs
Gary Chaulklin wrote: > 2/10/2007 Installed 0.99.5 using: > http://wireshark.osmirror.nl/download/win32/wireshark-setup-0.99.5.exe > > In addition to a few WinPcap 4.0 Setup errors in the attached, I got an > adware warning from McAfee (also in the attached). The adware message > appeared as the

Re: [Wireshark-users] WEP Authentication

2007-02-23 Thread Gerald Combs
ALEXANDRE GUIMARAES FERNANDES wrote: > I bought a WRT54G-LA - Linksys > Router to my office and > i´m trying to test my security. > How can a take a WEP Password in Wireshark ? Or any information of may > wep authentication ? There is any filter ? Y

Re: [Wireshark-users] wireshark without x server

2007-03-05 Thread Gerald Combs
Luca Rossi wrote: > Hi all, > is possible to use wireshark without a server X (in > command line only) > If yes what paramera i must settings? > Now when I try to use a wireshark i receved thi error: > (wireshark:21755): Gtk-WARNING **: cannot open > display: Try TShark: http://www.wireshark.org/d

Re: [Wireshark-users] unreadablity due to poor use of colours (Win32)

2007-03-15 Thread Gerald Combs
Stephen Fisher wrote: > On Fri, Mar 16, 2007 at 12:02:10AM +1100, Louis Solomon [SteelBytes] wrote: > >> just downloaded and installed latest release (0.99.5) on a w2k3 box >> that I remotly admin (via RDC). can't use it though, as the latest >> edition (unlike previous ver of wireshark that I

Re: [Wireshark-users] Fwd: error

2007-04-17 Thread Gerald Combs
fery nov wrote: > i have been downloaded wireshark using flashget but corrupt i think > file corrupt from server ..i attach the error screenshoot > plaese give me advise ... or solution. i have been update download > again..still corrupt. thanks! Have you tried downloading the file _without_

Re: [Wireshark-users] Barracuda false positive?

2007-04-17 Thread Gerald Combs
confirm that the Barracuda Web Filter appliance detects the stated > infection since version 0.99.2 up to 0.99.5... > > > *From*: Gerald Combs <[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>> > *Date*: Tue, 03 Oct 2006 09:11:17 -0700 > > I received a message from

Re: [Wireshark-users] Barracuda false positive?

2007-04-19 Thread Gerald Combs
The message has been included below. Username of poster: Gerald Combs Message Subject: Wireshark sbus.dll false positive? I've received a couple of reports from users that the Barracuda Web Filter has been triggering a false positives for each release of [url

Re: [Wireshark-users] Display filter

2007-05-02 Thread Gerald Combs
Irakli Natshvlishvili wrote: > Question: > > Using display filters is there a way to find if a particular string > occurs more then once in a packet? > > For example, if there is an UDP packet which has payload "this is one > 1234 two one test", then filtering via UDP contains "one" will display

Re: [Wireshark-users] Display filter

2007-05-02 Thread Gerald Combs
. Am I right? > > Do I understand correctly, that I need re-compile wireshark from the > source under windows to have regex support? > > If yes, than, well, sorry, I can't do it... > > --i.n. > > On 5/2/07, *Gerald Combs* <[EMAIL PROTECTED] > <mailto:[EMA

Re: [Wireshark-users] Display filter

2007-05-03 Thread Gerald Combs
Normally, the '.' metacharacter doesn't match line-ending characters. You can force it to span multiple lines using the 's' option, like so: (?s)Via.*Via Irakli Natshvlishvili wrote: > Sake, > > I modified the filter, "Via.*\x0d\x0aVia.*" does work for the capture > I've posted. > > But, wi

Re: [Wireshark-users] white text can't view selections

2007-05-16 Thread Gerald Combs
Ulf Lamping wrote: > [EMAIL PROTECTED] wrote: >> Hi, >> >> I've just downloaded and installed wirshark 0.99.5 onto my windows XP >> machine that already had ethereal 0.99.0. i can launch wireshark, but the >> text that should be vlack is white. This makes it impossible to read items >> such as inte

Re: [Wireshark-users] Wireshark Supported Protocols

2007-05-21 Thread Gerald Combs
Sake Blok wrote: > On Mon, May 21, 2007 at 12:16:46PM +0530, Kaushal Shriyan wrote: >> Can I have a list of supported protocols on Wireshark and does Wireshark >> supports smb protocol. > > I did a quick check on www.wireshark.org and wiki.wireshark.org. I did > not find a page with the supported

Re: [Wireshark-users] Installation problem.

2007-05-30 Thread Gerald Combs
A Kumar, Vijay (Vijay) wrote: > But make is now creating problem. After executing make I am getting > following error messages. > Root # /usr/ccs/bin/make > /usr/bin/perl ./make-version.pl . > Version configuration file version.conf not found. Using defaults. > This is not a SVN build. > svnversi

[Wireshark-users] Wireshark 0.99.6pre1 is now available

2007-06-22 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.6pre1 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.6pre1.tar.gz http://www.wireshark.org/download/prerelease/wireshark-

[Wireshark-users] Wireshark 0.99.6pre2 is now available

2007-06-29 Thread Gerald Combs
Wireshark 0.99.6pre2 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.6pre2.tar.gz http://www.wireshark.org/download/prerelease/wireshark-0.99.6pre2.u3p http://www.wireshark.org/downloa

[Wireshark-users] Wireshark conference

2007-06-29 Thread Gerald Combs
This is entirely hypothetical, but if someone were to host a 3-day Wireshark conference, what sort of sessions would you be interested in? If enough developers attended, would there be interest in a hackathon? ___ Wireshark-users mailing list Wireshark-u

[Wireshark-users] Wireshark 0.99.6 is now available

2007-07-05 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.6 has been released. What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development, and education. What's New Bug Fixes The following vulnerab

[Wireshark-users] Wireshark Windows installer updated to 0.99.6a

2007-07-09 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 A new Windows installer (wireshark-setup-0.99.6a.exe) has been released in order to fix a problem with updating from WinPcap 4.0 to 4.0.1. There are no other changes in the installer. The source code and U3 packages have not changed. The file size an

[Wireshark-users] GSM, NAS, and WCDMA analysis courses?

2007-07-12 Thread Gerald Combs
Can anyone recommend a good source for training for GSM, NAS, and WCDMA analysis with Wireshark? We (CACE and Wireshark University) have had a couple of requests for this recently. ___ Wireshark-users mailing list Wireshark-users@wireshark.org http://www

[Wireshark-users] We won an award!

2007-09-11 Thread Gerald Combs
Wireshark was awarded InfoWorld's 2007 BOSSIE (Best of Open Source Software) in the network protocol analysis category: http://www.infoworld.com/archives/t.jsp?N=s&V=91650 Congratulations to all of the developers and users over the years who made this happen! Wireshark has one of the best de

Re: [Wireshark-users] Opening Pix Syslog with Wireshark

2007-09-11 Thread Gerald Combs
[ Forwarded from wireshark-users-owner ] As far as I know, the PIX syslog output only contains summary data, e.g. IP addresses and port numbers. This doesn't provide enough information to reconstruct the network packet data required by Wireshark. There are many applications that can analyze sy

[Wireshark-users] Wireshark User's and Developer's conference update

2007-09-20 Thread Gerald Combs
SHARKFEST'08, the first ever Wireshark User's and Developer's conference, will be held March 31 to April 2, 2008 at Foothill College in Los Altos Hills, CA (in the bay area). Admission will be between $600 and $675, depending on when you register and if you have a CACE support contract. There wil

[Wireshark-users] [Fwd: Wireshark to K12 comparison]

2007-10-01 Thread Gerald Combs
[ Forwarding to wireshark-users ] Hello, I'm working for Alcatel-Lucent company in the Alcatel University department in France. I would like to study a training based on comparison between TDM SS7 signaling traces analysed by a K12-style interface and SS7 signaling on IP (SIGTRAN) traces analys

Re: [Wireshark-users] Problem with Windows Vista and Wireshark - FIXED1

2007-10-08 Thread Gerald Combs
The recommended solution is to make sure npf.sys is loaded before you start Wireshark: http://wiki.wireshark.org/CaptureSetup/CapturePrivileges#windows Wireshark contains over 1.4 million lines of code, and it's best to avoid running them as Administrator or root if you can. Kordogiannis Themisto

[Wireshark-users] What's so special about the number 12503?

2007-10-30 Thread Gerald Combs
Comcast (along with Sandvine) has been in the news recently for blocking Bittorrent (and apparently Notes and Google) traffic using forged TCP RSTs. Examples of this behavior can be found at the following locations: http://www.dslreports.com/forum/remark,18926539 http://forums.somethingawful.c

Re: [Wireshark-users] how to convert g729 RTP stream into anyplayableformat?

2007-11-07 Thread Gerald Combs
Joerg Mayer wrote: > On Wed, Nov 07, 2007 at 09:52:47PM +0100, PawelCarqowski wrote: >> > I believe it should not be license problem if I public just my stub code >> like an example. > > I think so too: As long as you only publish the source ther eshouldn't > be any problem. Although from lookin

Re: [Wireshark-users] Re : files permissions when using dumpcap with Multiple file

2007-11-15 Thread Gerald Combs
You might try writing the files to a directory with the setuid or setgid bit(s) set, along with the appropriate ownership. In the next release (0.99.7), dumpcap will attempt to change the ownership of capture files to that of the calling process. This makes it possible to install dumpcap setuid r

Re: [Wireshark-users] Re : Re : files permissions when using dumpcap with Multiple file

2007-11-16 Thread Gerald Combs
Patrick ANAT wrote: > For the second solution with version 0.99.7, there is still a problem: > the ownership of the calling process of dumpcap will be "root" since > wireshark is launched with "sudo wireshark". Then file will still be > owned by root. Maybe a solution will be to only use "sudo"

Re: [Wireshark-users] How do I go about creating a custompacket data decode

2007-11-21 Thread Gerald Combs
Owens, Neil wrote: > Steve > > It's for all UDP traffic on a specific port. I'm currently on Windows > XP, but if a flavour of Linux makes it easier, then so be it. In that case, you'd probably want to make a copy of the packet data, XOR it, and add the XORed data as a new data source for the pa

[Wireshark-users] Wireshark 0.99.7pre1 is now available

2007-11-21 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.7pre1 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.7pre1.tar.gz http://www.wireshark.org/download/prerelease/wireshark-

[Wireshark-users] Wireshark 0.99.7pre2 is now available

2007-11-29 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.7pre2 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.7pre2.tar.gz http://www.wireshark.org/download/prerelease/wireshark-

Re: [Wireshark-users] Problems with wireless decryption

2007-12-06 Thread Gerald Combs
Magee, Owen wrote: > I'm trying to use the 802.11 wireless decryption features in Wireshark > without much luck. We're using Wireshark 0.99.6a on Windows XP with the > AirPCap Wi-Fi capture card. It can capture non-encrypted data fine. > However, I'm trying to decrypt a CCMP/AES/WPA2 encrypted ne

Re: [Wireshark-users] IEEE 802.11 wpa-pwd seems to break if I add a time reference (using 0.99.6)

2007-12-06 Thread Gerald Combs
Jeff Clemmer wrote: > Hello, > > I'm using wireshark version 0.99.6, sniffing WLAN on linux. I noticed > if I set a relative time reference on a packet, the decryption of wpa > (using the wpa-pwd option in Key #1) seems to break. If I reload the > file (so that the reference is gone), the decryp

[Wireshark-users] Wireshark 0.99.7 is now available

2007-12-18 Thread Gerald Combs
I'm proud to announce the release of Wireshark 0.99.7. I'm also proud to announce Sharkfest '08, the first-ever Wireshark users and developers conference, and SharkNet, an enterprise maintenance and support program for Wireshark. Shameless Promotion Sharkfest '08 will be held March 31 to Apri

Re: [Wireshark-users] Wireshark 0.99.7 is now available

2007-12-18 Thread Gerald Combs
[EMAIL PROTECTED] wrote: > Hi, > > When clicking on the download button on the webpage it still 0.996a we get... The web pages and scripts on the server link to 0.99.7. Is is possible that an older version of the page is being cached by your browser or proxy server? __

Re: [Wireshark-users] Wireshark 0.99.7 is now available

2007-12-18 Thread Gerald Combs
Frankel, Stewart wrote: > I did the upgrade from the download link and Help about shows: > > > Version 0.99.5 (SVN Rev 20677) > > Copyright 1998-2007 Gerald Combs <[EMAIL PROTECTED]> and > contributors. > This is free software; see the source for copying condit

Re: [Wireshark-users] Fwd: Cannot receive all packet from different cpu.

2008-01-04 Thread Gerald Combs
Jack Jackson wrote: > At 03:21 PM 1/4/2008, jbartas wrote: >> Hubs are getting hard to find everywhere - in the US, Ebay is one >> source. For the last year I've been collecting every hub I see (both 10 >> and 100) at junk stores, yards sales, even friends throwing them away >> because they are

Re: [Wireshark-users] message fragment in message overview forBICCpackets

2008-01-18 Thread Gerald Combs
Joerg Mayer wrote: > On Fri, Jan 18, 2008 at 12:11:35PM +, Peter Cambouris wrote: >> Take me off the list pls > > Please read the footer that is appended to each and every mail on > how to do that yourself. Would it be useful to have an explicit unsubscribe link, e.g. mailto:[EMAIL PROTECTED]

Re: [Wireshark-users] WLAN APC file and RSSI

2008-01-22 Thread Gerald Combs
Avi Berkovich wrote: > Hello, > > Wireshark doesn't display the RSSI value in dBm, only in percent. > This happens with APC files captured with Airopeek. > > Is this a limitation? Are you sure the dBm values are present in the capture file? According to http://www.wildpackets.com/elements/white

Re: [Wireshark-users] WLAN APC file and RSSI

2008-01-22 Thread Gerald Combs
It looks like the dBm tag isn't supported in Wireshark. Do you have a capture file you can send to the list or upload to the wiki? Avi Berkovich wrote: > First, thanks for the link. > > As for the dBm value, it is present in the capture file (stored right > after the percentage value in the pac

Re: [Wireshark-users] RSSI values

2008-02-01 Thread Gerald Combs
Kevin Janaes wrote: > I have a AirPcap card on a windows machine. I am trying to find the > RSSI values from wireshark or tshark but not having any luck. Is it > possible with this setup? What capture type is enabled for your adapter? If it's "802.11 Only", then you won't see any RSSI values.

Re: [Wireshark-users] Wireshark sold on ebay

2008-02-11 Thread Gerald Combs
Ulf Lamping wrote: > You are perfectly right - as long as the terms of the GPL are fulfilled, > this is ok for me! The phrase "I am authorized reseller for this software" at the end of the auction description is misleading. Wireshark University and CACE have permission to use the trademark for

Re: [Wireshark-users] Wireshark sold on ebay

2008-02-12 Thread Gerald Combs
Ruben Junkie wrote: > So I was lurking around eBay and found that seller redlinedit > is selling copies of wireshark > which is totally wrong ... this people who think that they can take > advantage of free distributed software must be stopped ... > > h

[Wireshark-users] Wireshark 0.99.8pre1 is now available

2008-02-18 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.8pre1 is now available for testing. Windows installers and source code can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-setup-0.99.8pre1.exe http://www.wireshark.org/download/prerelease/wireshark

Re: [Wireshark-users] [Wireshark-announce] Wireshark 0.99.8pre1 is now available

2008-02-19 Thread Gerald Combs
This should be fixed now. Rob Carmichael wrote: > Hi, > > The release notes link is broken. > > regards, > > Rob Carmichael > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Wireshark > announcements > Sent: 19 February 2008 06:36 > To: Wireshark

[Wireshark-users] Vint Cert to speak at Sharkfest

2008-02-19 Thread Gerald Combs
We are excited to announce that Dr. Vinton Cerf, PhD, Google Vice President and Chief Internet Evangelist will open day 2 of Sharkfest with a talk entitled "Non-discriminatory Network Service." Dr. Cerf is considered by many to be the father of the Internet. When he's not giving talks on matters th

[Wireshark-users] Wireshark 0.99.8 is now available

2008-02-27 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I'm proud to announce the release of Wireshark 0.99.8. Sharkfest Reminder ~ Sharkfest '08 will be held March 31 to April 2 in Los Altos Hills, ~ CA. At Sharkfest you'll have the opportunity to meet many of the ~ people behind Wireshark and WinP

Re: [Wireshark-users] build problem

2008-02-28 Thread Gerald Combs
Jeff Morriss wrote: >> So we need with-libpcap and without, with gtk1 or gtk2? >> So the Mac OS X buildbot could build >> - gtk2 without libpcap >> - gtk1 with libpap >> (I'm not sure if gtk1 without libpcap makes much sense)... I've added extra steps to the OS X buildbot to configure and compile

Re: [Wireshark-users] Wireshark to obtain password (Yahoo Mail -> Ypops -> Outlook)

2008-03-03 Thread Gerald Combs
Daniel at EnigmaBiz wrote: > Or is there a open source or software out there to reveal the password > that’s been saved > > as asterisk in outlook? Protected Storage PassView (http://www.nirsoft.net/utils/pspv.html) is supposed to do this. I haven't tried it myself. _

[Wireshark-users] Wireshark 1.0.0pre1 is now available

2008-03-18 Thread Gerald Combs
Wireshark 1.0.0pre1 is now available for testing. Installers for Windows, OS X, and source code can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-setup-1.0.0pre1.exe http://www.wireshark.org/download/prerelease/wireshark-1.0.0pre1.u3p http://www.wireshark.or

[Wireshark-users] Wireshark 1.0 is now available

2008-03-31 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I'm proud to announce the release of Wireshark 1.0. This is the culmination of nearly ten years of hard work by a team of brilliant and talented developers. It is an honor to be able to work with these people. On behalf of the development team, I woul

[Wireshark-users] Wireshark 2.9.0 is now available

2018-12-12 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.9.0. This is an experimental release intended to test new features for Wireshark 3.0. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education.

[Wireshark-users] Wireshark 2.6.6 is now available

2019-01-08 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.6.6. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New • The Windows installers now ship with Qt 5.9.7. Previously they

[Wireshark-users] Wireshark 2.4.12 is now available

2019-01-08 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.4.12. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. _

Re: [Wireshark-users] signatures for 2.4.12 release not accessible

2019-01-09 Thread Gerald Combs
Fixed. On 1/9/19 8:19 AM, Robert Frohl wrote: > Hi all, > > the signatures for the new 2.4.12 release are visible on the webserver, > but can't be accessed. Does someone know who I need to talk to, to get > this resolved? > > As far as I have tested the other signatures are not affected. > > >

[Wireshark-users] Wireshark 3.0.0rc1 is now available

2019-02-15 Thread Gerald Combs
I'm proud to announce the release of Wireshark 3.0.0rc1. This is the first release candidate for Wireshark 3.0. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New Many use

[Wireshark-users] Wireshark 3.0.0rc2 is now available

2019-02-22 Thread Gerald Combs
I'm proud to announce the release of Wireshark 3.0.0rc2. This is the second release candidate for Wireshark 3.0. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New Many us

[Wireshark-users] Wireshark 2.6.7 is now available

2019-02-27 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.6.7. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New Bug Fixes The following vulnerabilities have been fixed: •

[Wireshark-users] Wireshark 2.4.13 is now available

2019-02-27 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.4.13. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. _

[Wireshark-users] Wireshark 3.0.0 is now available

2019-02-28 Thread Gerald Combs
I'm proud to announce the release of Wireshark 3.0.0. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New Many user interface improvements have been made. See the “New and

Re: [Wireshark-users] signatures for 2.4.13 missing

2019-03-06 Thread Gerald Combs
On 3/6/19 2:56 AM, Robert Frohl wrote: > Hi, > > the signatures file for the new 2.4.13 release [0] only contains > archives for the 2.6.7 release. Can someone look into this please? It's been updated with content for 2.4.13. Thanks! ___

[Wireshark-users] Wireshark 2.6.8 is now available

2019-04-08 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.6.8. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New Bug Fixes The following vulnerabilities have been fixed: •

[Wireshark-users] Wireshark 2.4.14 is now available

2019-04-08 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.4.14. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. _

[Wireshark-users] Wireshark 3.0.1 is now available

2019-04-08 Thread Gerald Combs
I'm proud to announce the release of Wireshark 3.0.1. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New • The Windows installers now ship with Npcap 0.992. They previousl

[Wireshark-users] Volunteers and ideas needed for Google Season of Docs

2019-04-10 Thread Gerald Combs
Google recently announced its Season of Docs[1], a project similar to the Summer of Code which is intended to help technical writers and open source projects work together. I think it would be a great idea for Wireshark participate, and in order to do so we need the following[2]: Two or more or

[Wireshark-users] Wireshark 3.0.2 is now available

2019-05-22 Thread Gerald Combs
I'm proud to announce the release of Wireshark 3.0.2. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New • The Windows installers now ship with Qt 5.12.3. They previously

[Wireshark-users] Wireshark 2.6.9 is now available

2019-05-22 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.6.9. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New Bug Fixes The following vulnerabilities have been fixed: •

[Wireshark-users] Wireshark 2.4.15 is now available

2019-05-22 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.4.15. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. _

[Wireshark-users] Wireshark 2.6.10 is now available

2019-07-17 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.6.10. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New Bug Fixes The following vulnerabilities have been fixed:

[Wireshark-users] Wireshark 2.4.16 is now available

2019-07-17 Thread Gerald Combs
I'm proud to announce the release of Wireshark 2.4.16. __ What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. _

[Wireshark-users] Wireshark 3.0.3 is now available

2019-07-17 Thread Gerald Combs
I'm proud to announce the release of Wireshark 3.0.3. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. What’s New • The Windows installers now ship with Qt 5.12.4. They previously

  1   2   >