>>>>> "Volf," == Volf, Frank <[EMAIL PROTECTED]> writes:
Volf,> I once did a different approach, I made a patch to ipmon to write IP packets
Volf> to a file format that can be read by tcpdump. I even made to tcpdump so it
Volf> could read and print these files).
patch appreciated...
Volf> It works as that tcpdump can indeed read the file and decode the packets. I
Volf> got stuck however trying to find out how the pcap compiler should be changed
Volf> so you can apply tcpdump packet filter expressions on such a file, so you
Volf> can currently only dump the entire file.
I've used tcpdump 3.6 on files like that.
Did you do this on 0.6/3.6?
] ON HUMILITY: to err is human. To moo, bovine. | firewalls [
] Michael Richardson, Sandelman Software Works, Ottawa, ON |net architect[
] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[
] panic("Just another NetBSD/notebook using, kernel hacking, security guy"); [
-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe