[tcpdump-workers] NFS and TCP port numbers

2006-02-16 Thread alexander medvedev
hallo, i am wondering whether tcpdump should print rpc xid numbers instead of TCP port numbers in TCP NFS packets. check out the port numbers in the following dump: 12:27:39.078026 IP x.x.99.25.5001 > x.x.99.26.5002: . ack 29 win 65535 12:27:39.088348 IP x.x.99.26.5001 > x.x.99.25.2049: . ack 70

Re: [tcpdump-workers] What is the main reason in absent append

2006-02-16 Thread Guy Harris
On Feb 16, 2006, at 12:06 PM, Stephen Donnelly wrote: The biggest problem I imagine is that the resulting file would have only one header block, so the configuration of the capture for the appended records would have to be the same as for the original file. I'm not sure how you could check f

Re: [tcpdump-workers] What is the main reason in absent append

2006-02-16 Thread Stephen Donnelly
On Thu, 2006-02-16 at 20:17 +0300, Mikhail Manuylov wrote: > Hi there, > > All I wonder is why tcpdump still hasn't any binary dump append feature. The biggest problem I imagine is that the resulting file would have only one header block, so the configuration of the capture for the appended recor

[tcpdump-workers] multiple libpcap ring buffers?

2006-02-16 Thread J.O. Leger
Hey, If I have an application that opens two packet capturing sessions(ie eth0 and eth1) using the ring buffer version of libpcap, does libpcap create two separate ring buffers? Thanks for your help Cheers ___ Join Excite! - http:/

[tcpdump-workers] PATCH DCCP translate service code to host byte order

2006-02-16 Thread Andrea Bittau
The DCCP service code is a u32 in network byte order. The current DCCP code does not call htonl() or equivalent. Fix attached. --- diff -crN tcpdump/print-dccp.c tcpdump-sorbo/print-dccp.c *** tcpdump/print-dccp.cMon Dec 5 21:36:24 2005 --- tcpdump-sorbo/print-dccp.c Wed Jan 25 10:34:

Re: [tcpdump-workers] What is the main reason in absent append capabilities

2006-02-16 Thread Ed Maste
On Thu, Feb 16, 2006 at 10:56:26AM -0800, Guy Harris wrote: > Mikhail Manuylov wrote: > > >All I wonder is why tcpdump still hasn't any binary dump append feature. > > Because nobody who needed that capability wrote code to implement it and > contributed it to tcpdump-workers? I've just discov

Re: [tcpdump-workers] What is the main reason in absent append capabilities

2006-02-16 Thread Guy Harris
Mikhail Manuylov wrote: All I wonder is why tcpdump still hasn't any binary dump append feature. Because nobody who needed that capability wrote code to implement it and contributed it to tcpdump-workers? - This is the tcpdump-workers list. Visit https://lists.sandelman.ca/ to unsubscribe.

[tcpdump-workers] What is the main reason in absent append capabilities of tcpdump and libpcap?

2006-02-16 Thread Mikhail Manuylov
Hi there, All I wonder is why tcpdump still hasn't any binary dump append feature. A got some facts and thoughts: Implemetation of mentioned above feature is just a sligtly change to libcap's "savefile.c" ( i. e. addition of pcap_dump_open_append or add append flag to pcap_dump_open ( first won't

[tcpdump-workers] tcpdump.org

2006-02-16 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Oh, I have removed the A record and the MX record for "tcpdump.org" The only address there was [EMAIL PROTECTED] If someone would like to run a well spam-filtered interface, I'll restore the MX record, but the spam level is rather high. (1 user

Re: [tcpdump-workers] testing the list

2006-02-16 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 > "Michael" == Michael Richardson <[EMAIL PROTECTED]> writes: Michael> This is another test of the mailing list. I don't know what I did wrong. But, it is fixed now. A kind gentleman was doing the spam moderation on the list last year.

[tcpdump-workers] testing the list

2006-02-16 Thread Michael Richardson
This is another test of the mailing list. - This is the tcpdump-workers list. Visit https://lists.sandelman.ca/ to unsubscribe.