Re: [Wireshark-users] bogus LLC header in UDP packet

2007-01-30 Thread Jaap Keuter
Hi, According to RFC 2353 this decoding is correct. See paragraph 2.6.1. These UDP/TCP ports are assigned by IANA to this protocol. It is implemented as such in the LLC dissector. Thanx, Jaap On Tue, 30 Jan 2007, Martin Pokorny wrote: > Hi, > > I think I may have stumbled onto a wireshark bug (

Re: [Wireshark-users] [ANNOUNCE] WinPcap 4.0 has been released

2007-01-30 Thread Stephen Fisher
On Tue, Jan 30, 2007 at 10:33:51PM -0200, Persio Pucci wrote: > Maybe I am a little late for that, but also, would that be possible to > add IO graphs the possibility to select bits (kbps) to the Y axis? :D > > Hope I am not asking too much... or maybe 0.99.6 ;) > > On 1/30/07, Persio Pucci <[E

Re: [Wireshark-users] [ANNOUNCE] WinPcap 4.0 has been released

2007-01-30 Thread Ulf Lamping
Persio Pucci wrote: > Hey, maybe somebody asked for it already... but would that be possible > to include in 0.99.5 a way to export IO graphs to any graphic file > format (GIF, JPG, PNG, BMP, etc)? > Definitely not in the 0.99.5 - it's in the release process quite ahead. Any new feature will b

[Wireshark-users] bogus LLC header in UDP packet

2007-01-30 Thread Martin Pokorny
Hi, I think I may have stumbled onto a wireshark bug (ethereal version 0.99.0, libpcap version 0.8.3 on RHEL4). An application on which I'm working is receiving UDP packets over gigabit Ethernet from some custom hardware. The packets have a fixed source and destination UDP port number, which

Re: [Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Guy Harris
On Jan 30, 2007, at 4:13 PM, Ulf Lamping wrote: > BTW: Acterna was bought by JDSU and was formerly Wavetek Wandel > Goltermann / TTC, according to > http://www.wildpackets.com/products/free_utilities/proconvert/file_types And, according to http://telephonyonline.com/backoffice/print/tel

[Wireshark-users] Wireshark 0.99.5pre2 is now available

2007-01-30 Thread Gerald Combs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wireshark 0.99.5pre2 is now available for testing. Source code and a Windows installer can be downloaded immediately from http://www.wireshark.org/download/prerelease/wireshark-0.99.5pre2.tar.gz http://www.wireshark.org/download/prerelease/wireshark-

Re: [Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Persio Pucci
ProConvert did the job just fine, just to let you guys know. I am really glad I've found this forum, Wireshark is just a tremendous tool, light-years ahead of any other. I really pretend to help out on the forum, I just love this tool. Persio On 1/30/07, Ulf Lamping <[EMAIL PROTECTED]> wrote:

Re: [Wireshark-users] [ANNOUNCE] WinPcap 4.0 has been released

2007-01-30 Thread Persio Pucci
Maybe I am a little late for that, but also, would that be possible to add IO graphs the possibility to select bits (kbps) to the Y axis? :D Hope I am not asking too much... or maybe 0.99.6 ;) On 1/30/07, Persio Pucci <[EMAIL PROTECTED]> wrote: Hey, maybe somebody asked for it already... but w

Re: [Wireshark-users] [ANNOUNCE] WinPcap 4.0 has been released

2007-01-30 Thread Persio Pucci
Hey, maybe somebody asked for it already... but would that be possible to include in 0.99.5 a way to export IO graphs to any graphic file format (GIF, JPG, PNG, BMP, etc)? Persio On 1/30/07, Gerald Combs <[EMAIL PROTECTED]> wrote: Whoah there! :) I just copied WinPcap 4.0 into the 0.99.5 t

Re: [Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Ulf Lamping
Guy Harris wrote: > Persio Pucci wrote: > > >> is there a way to open in Wireshark files captured by an Acterna packet >> analyzer in a Frame Relay interface? >> > > The list of file formats supported by Wireshark can be found at > > http://wiki.wireshark.org/FileFormatReference > >

Re: [Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Ulf Lamping
Murali Raju wrote: > Give ProConvert a shot - > http://www.wildpackets.com/products/free_utilities/proconvert/overview > I've added a link to the Wiki Tools and FileFormatReference pages. Regards, ULFL ___ Wireshark-users mailing list Wireshark-users@

Re: [Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Persio Pucci
Hi, I'll give ProConverter a try to see if it works. also I'll forward to Luis a couple of files on its format, to see what is wrong. Thank you all. Persio On 1/30/07, Guy Harris <[EMAIL PROTECTED]> wrote: Persio Pucci wrote: > is there a way to open in Wireshark files captured by an Acter

Re: [Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Guy Harris
Persio Pucci wrote: > is there a way to open in Wireshark files captured by an Acterna packet > analyzer in a Frame Relay interface? The list of file formats supported by Wireshark can be found at http://wiki.wireshark.org/FileFormatReference It doesn't explicitly list Acterna's format

Re: [Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Murali Raju
Give ProConvert a shot - http://www.wildpackets.com/products/free_utilities/proconvert/overview Thanks! _Raju On 1/30/07, Persio Pucci <[EMAIL PROTECTED]> wrote: > Hello folks, > > is there a way to open in Wireshark files captured by an Acterna packet > analyzer in a Frame Relay interface? > >

Re: [Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Luis Ontanon
If you send in some files (binary and decoded text) we maybe able to reverse engineer the format and add support for them. On 1/30/07, Persio Pucci <[EMAIL PROTECTED]> wrote: > Hello folks, > > is there a way to open in Wireshark files captured by an Acterna packet > analyzer in a Frame Relay inte

Re: [Wireshark-users] [ANNOUNCE] WinPcap 4.0 has been released

2007-01-30 Thread Gerald Combs
Whoah there! :) I just copied WinPcap 4.0 into the 0.99.5 trunk, and plan on releasing 0.99.5pre2 later today. I'll send a message when it's ready. I'm hoping to have 0.99.5 final out on Thursday or Friday. Jaap Keuter wrote: > Hi List, > > On the back of WinPCap 4.0 our fearless leader has

Re: [Wireshark-users] Gdk-ERROR **: file gdkdisplay-win32.c: line 72 (wireshark 0.99.4 on windows server 2003)

2007-01-30 Thread Enyuan.Wu
Hi Jaap, Thanks for your effort. I would like to say yes, you are right! NetOp is the point! And I start Wireshark on my virtual PC for hours, without problem! Thanx, Enyuan -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jaap Keuter Sent: Montag, 22.

Re: [Wireshark-users] [ANNOUNCE] WinPcap 4.0 has been released

2007-01-30 Thread Jaap Keuter
Hi, Ahh crap, I thought Gerald was holding of until the new WinPcap. Hope he does that soon then. Thanx, Jaap On Tue, 30 Jan 2007, Jeff Morriss wrote: > > Note that WinPcap 4.0 didn't go in until rev 20622 which isn't up in the > prerelease directory. > > Jaap Keuter wrote: > > Hi List, > > > >

[Wireshark-users] Exporting IO Graphs

2007-01-30 Thread Persio Pucci
Hi there, it's me again. Is there anyway to export IO graphs to image files? That would help a lot on reports. Regards, Persio ___ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-users

Re: [Wireshark-users] Y axis "advanced" fields

2007-01-30 Thread Persio Pucci
UlfL, well, I really can doit, if only I understand how does it work :) Regards, Persio On 1/30/07, Ulf Lamping <[EMAIL PROTECTED]> wrote: Persio Pucci wrote: > Hello again, > > is there nay good documentation on how to use Wireshark's IO Graphs Y > axis advanced fields? > The "best" you can

Re: [Wireshark-users] Y axis "advanced" fields

2007-01-30 Thread Ulf Lamping
Persio Pucci wrote: > Hello again, > > is there nay good documentation on how to use Wireshark's IO Graphs Y > axis advanced fields? > The "best" you can get is at http://www.wireshark.org/docs/wsug_html_chunked/ChStatIOGraphs.html Why not write it yourself and share it with us? Regards, UL

[Wireshark-users] Y axis "advanced" fields

2007-01-30 Thread Persio Pucci
Hello again, is there nay good documentation on how to use Wireshark's IO Graphs Y axis advanced fields? Regards, Persio ___ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-users

[Wireshark-users] Opening Acterna WAN capture files in wireshark

2007-01-30 Thread Persio Pucci
Hello folks, is there a way to open in Wireshark files captured by an Acterna packet analyzer in a Frame Relay interface? Regards, Persio ___ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshar

[Wireshark-users] [kerberos]e-date field is not parsered in krb-erorr packet

2007-01-30 Thread Xiaoguang Liu
please check the two cap file attached. there is a e-data at the end of the last frame in both files. there is a NTstatus code is the e-date file. but Wireshark parsered the one in KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN.cap but not "KRB5KDC_ERR_CLIENT_REVOKED for AS.cap". the NTstatus code is very helpf

Re: [Wireshark-users] "error while loading "dfilter_macro':No such file or directory"

2007-01-30 Thread Luis Ontanon
As a workarround please put an empty file in the dir called dfilter_macros in wireshark's directory. As soon as I re-stabilize the code I'm working on, i'll checkin a fix. Luis On 1/30/07, Xiaoguang Liu <[EMAIL PROTECTED]> wrote: > Version 0.99.6-SVN-20621 (SVN Rev 20621) on win xp sp2 > > every t

[Wireshark-users] "error while loading "dfilter_macro':No such file or directory"

2007-01-30 Thread Xiaoguang Liu
Version 0.99.6-SVN-20621 (SVN Rev 20621) on win xp sp2 every time openning wireshark, I saw the erorr message in subject and I have to click OK to continue. any idea? ___ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.or

Re: [Wireshark-users] [ANNOUNCE] WinPcap 4.0 has been released

2007-01-30 Thread Jeff Morriss
Note that WinPcap 4.0 didn't go in until rev 20622 which isn't up in the prerelease directory. Jaap Keuter wrote: > Hi List, > > On the back of WinPCap 4.0 our fearless leader has made a new prerelease > http://www.wireshark.org/download/prerelease/wireshark-setup-0.99.5pre2-20620.exe > with a