Re: [Wireshark-dev] develop a tool to parse captured file

2007-07-03 Thread Abhik Sarkar
Hello Yefim, For the Ethereal native file format (libpcap/WindPcap), this is a starting point: http://wiki.wireshark.org/Development/LibpcapFileFormat Alternately, you could convert the captures to PDML format (an XML based format) which would make the packets easier to process (as in simpler

Re: [Wireshark-dev] Windows build crashing

2007-07-03 Thread Graham Bloice
Jim Pickering wrote: The build environment is Visual C++ 2005 Express Edition. I built adns_dll.dll with Visual C++ 2005 Express Edition and relinked wireshark, as suggested. Wireshark still crashes when loading a previously saved capture file or when starting a new capture. Are you

[Wireshark-dev] how to disable dissectors when I build TShark ?

2007-07-03 Thread Jean-Grégoire Foulon
Hi, I would like to know if there is an easy way to disable dissectors when I compile Tshark. I am compiling it for an embedded architecture and libwireshark is a tad too big, I would like to have a much smaller version. I only need some of the protocols. I started to remove dissectors by hand

Re: [Wireshark-dev] how to disable dissectors when I build TShark ?

2007-07-03 Thread Sebastien Tandel
Hi, I would like to know if there is an easy way to disable dissectors when I compile Tshark. No, there isn't. It's not the first time it has been asked here. Unfortunately, there is no development project towards this direction for now (at least not known). I am compiling it for an

[Wireshark-dev] [ANNOUNCE] WinPcap 4.0.1 has been released

2007-07-03 Thread Gianluca Varenni
As of today, WinPcap 4.0.1 is available in the download section of the WinPcap website, http://www.winpcap.org/install/ . This maintenance release addresses a security vulnerability reported by the iDefense Labs. Full details can be found in the change log attached at the end of this message.

[Wireshark-dev] [ANNOUNCE] WinPcap 4.1 beta has been released

2007-07-03 Thread Gianluca Varenni
As of today, WinPcap 4.1 beta is available in the download section of the WinPcap website, http://www.winpcap.org/install/ . This software release contains some important security bug fixes to the kernel driver, as well as the update of libpcap to the 0.9.6 branch. Also, it includes some

Re: [Wireshark-dev] Windows build crashing

2007-07-03 Thread Jim Pickering
Crashes on line 650 ... handle = (HANDLE) _get_osfhandle (pipe_input-source); in gui_utils.c. Second time through loop (iterations == 1). First time through loop, pipe_input-pipe_input_id = 0; (line 668) if that means anything. Jim Jim Pickering Senior Software Engineer SRI International

Re: [Wireshark-dev] Windows build crashing

2007-07-03 Thread Jim Pickering
crashes in msvcr80.dll get_osfhandle() with an invalid parameter (pipe_input-source = 3) Jim Pickering Senior Software Engineer SRI International 4119 Broad Street, Suite 210 San Luis Obispo, CA 93401 Phone: (805) 542-9330 ext. 125 FAX: (805) 546-2444 Jim Pickering wrote: Crashes on line 650

Re: [Wireshark-dev] 0.99.6 release postponed

2007-07-03 Thread Jaap Keuter
Hi, Now that WinPcap 4.0.1 is out a release of 0.99.pre3 is possible. I would like to request holding off until I've got the debian packaging updates from Frederic Peters in, which I've got lined up in my working copy. Tomorrow morning, when I'm fresh and sober, I'll review them one last time

Re: [Wireshark-dev] Windows build crashing

2007-07-03 Thread Jim Pickering
Never mind! Thanks for the help. Wasn't building zlib.dll for some reason. Jim Jim Pickering Senior Software Engineer SRI International 4119 Broad Street, Suite 210 San Luis Obispo, CA 93401 Phone: (805) 542-9330 ext. 125 FAX: (805) 546-2444 Jim Pickering wrote: The build environment is

Re: [Wireshark-dev] 0.99.6 release postponed

2007-07-03 Thread Gerald Combs
No problem. Tomorrow's a U.S. holiday, and I've been assigned Brisket Duty. :) Jaap Keuter wrote: Hi, Now that WinPcap 4.0.1 is out a release of 0.99.pre3 is possible. I would like to request holding off until I've got the debian packaging updates from Frederic Peters in, which I've got

Re: [Wireshark-dev] how to disable dissectors when I build TShark ?

2007-07-03 Thread Jean-Grégoire Foulon
On 7/3/07, Sebastien Tandel [EMAIL PROTECTED] wrote: Hi, I would like to know if there is an easy way to disable dissectors when I compile Tshark. No, there isn't. It's not the first time it has been asked here. Unfortunately, there is no development project towards this direction for now

[Wireshark-dev] Wireshark 99.5 for HP-UX

2007-07-03 Thread Selva, Suren
Any idea where I can get 99.5 for HP-UX? I have been unsuccessful in my attempts so far to get 9.5 for HP. Best Regards, Suren Selva Unix Systems Administrator Phone: (630) 718-5182 Email: [EMAIL PROTECTED] CONFIDENTIALITY NOTICE: This message (including any attachments) may contain Molex