[Wireshark-users] Wireshark Supported Protocols

2007-05-21 Thread Kaushal Shriyan
Hi Can I have a list of supported protocols on Wireshark and does Wireshark supports smb protocol. Thanks and Regards Kaushal ___ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-users

[Wireshark-users] measuring a latency across the network

2007-05-21 Thread Korn Vajanapoom
I run two instances of wiresharks at two end nodes to measure a packet latency across the network. So, I have two log files, one with time stamps at the transmitting end, and the other one with time stamps at the receiving end. The latency for each packet is simply a time difference between two

Re: [Wireshark-users] Wireshark Supported Protocols

2007-05-21 Thread Sake Blok
On Mon, May 21, 2007 at 12:16:46PM +0530, Kaushal Shriyan wrote: Can I have a list of supported protocols on Wireshark and does Wireshark supports smb protocol. I did a quick check on www.wireshark.org and wiki.wireshark.org. I did not find a page with the supported protocols. Could someone

Re: [Wireshark-users] Wireshark Supported Protocols

2007-05-21 Thread ronnie sahlberg
unless you are a developer of a new prototype protocol it is likely wireshark supports any and every protocol you will ever encounter. wireshark has the without doubt most complete dissector for SMB of any network analyzer available. On 5/21/07, Kaushal Shriyan [EMAIL PROTECTED] wrote: Hi

[Wireshark-users] Wireshark problem with installation of solaris package-- checkinstall script did not complete successfully

2007-05-21 Thread arthy geraldin
Hi all, I have installed wireshark-0.99.4 in Solaris10. I wanted to generate a solaris package which can be used to install wireshark from package in another system instead of installing from source. I gave the command make solaris-package and it generated the package

[Wireshark-users] Wireshark problem with installation of solaris package-- checkinstall script did not complete successfully

2007-05-21 Thread arthy geraldin
Hi all, I have installed wireshark-0.99.4 in Solaris10. I wanted to generate a solaris package which can be used to install wireshark from package in another system instead of installing from source. I gave the command make solaris-package and it generated the package

[Wireshark-users] Decoding RFC1950 compressed data?

2007-05-21 Thread Andreas Weller
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Hi! A friend of mine got a new PC system at his shop. It's a Linux based client/server system. As it is undocumented black box stuff we used wireshark to decode its datastream :-) We learned that the clients connect to the server using PostgreSQL

[Wireshark-users] Problems INSTALLING 0.99.6

2007-05-21 Thread mattia tomasoni
Hi everybody; have been trying to configure and install the 0.99.6 (beta) version; here is what I get: -- # ./configure --disable-gtk2 checking build system type...

[Wireshark-users] a question about Raw packet data, message: No links data avaiable

2007-05-21 Thread Alexander Bubnov
Hello! Can you please help me to find out...? I have downloaded RawPacketIPv6Tunnel-UK6x.cap from http://wiki.wireshark.org/SampleCaptures page. Below you can see the desription from that site: RawPacketIPv6Tunnel-UK6x.cap (libpcap) - Some IPv6 packets captured from the 'sit1' interface on

Re: [Wireshark-users] Problems INSTALLING 0.99.6

2007-05-21 Thread Joerg Mayer
On Mon, May 21, 2007 at 04:08:04PM +0200, mattia tomasoni wrote: # ./configure --disable-gtk2 ... checking for C compiler default output file name... configure: error: C compiler cannot create executables See `config.log' for more details. ... configure:3100: checking for C compiler default

Re: [Wireshark-users] a question about Raw packet data, message: No links data avaiable

2007-05-21 Thread Guy Harris
Guy Harris wrote: It means we couldn't come up with a better name for it. :-) It might make more sense to have the dissector for raw IP not put anything into the protocol tree, and just call the IPv4 or IPv6 dissector. It would mean that if a file format that supported multiple link layer

[Wireshark-users] cut short in the middle of a packet issue

2007-05-21 Thread Prashanth
Hello, I am using wireshark to read in a .trc file that was generated from a fileserver (netapp) that generated dump in trc format for analysis. In some instance i see the following: [EMAIL PROTECTED]:~/work % /local/wireshark/bin/tshark -r vif1.trc -z 'ip_hosts,tree' -q tshark: vif1.trc

Re: [Wireshark-users] cut short in the middle of a packet issue

2007-05-21 Thread Guy Harris
Prashanth wrote: I am using wireshark to read in a .trc file that was generated from a fileserver (netapp) that generated dump in trc format for analysis. trc format is just libpcap format. In some instance i see the following: [EMAIL PROTECTED]:~/work % /local/wireshark/bin/tshark -r

Re: [Wireshark-users] cut short in the middle of a packet issue

2007-05-21 Thread Prashanth
Guy, Thanks for your response. Yes, i stop the trace on the filer before reading the file. If wireshark ignores the packet then why doesn't it print the ip_hosts stats? Is that the expected behavior? I normally use the -q because i am more interested in looking at the stats by IP address.

Re: [Wireshark-users] cut short in the middle of a packet issue

2007-05-21 Thread Guy Harris
Prashanth wrote: Yes, i stop the trace on the filer before reading the file. Then there's a bug on the filer; you should report it to NetApp. It might not be writing out the last bufferful of packet data (which means there might be some packets that are *completely* missing from the file).

Re: [Wireshark-users] Decoding RFC1950 compressed data?

2007-05-21 Thread Stephen Fisher
On Mon, May 21, 2007 at 03:49:17PM +0200, Andreas Weller wrote: A friend of mine got a new PC system at his shop. It's a Linux based client/server system. As it is undocumented black box stuff we used wireshark to decode its datastream :-) :) But it also connect to port 1536 using some

Re: [Wireshark-users] Help with Output TCP Dup ACK3#2 1320 22 ACK

2007-05-21 Thread Stephen Fisher
On Fri, May 18, 2007 at 03:57:01PM -0600, Mike Ciccone wrote: I am having a problem with SSH. I can ssh from some server but not others. I verified that there are no access-lists blocking from doing this. When I ran Wireshark on my pc and tried to ssh to the server I get the following

Re: [Wireshark-users] Help with Output TCP Dup ACK3#2 1320 22 ACK

2007-05-21 Thread Visser, Martin
Duplicate ACKs are fairly common, so they don't always indicate a problem. During normal congestion you will receive duplicate ACKs if the far end has not received a TCP segment it believes it should have. It also can be used to keep alive a connection. However if you get dup ACKs consistently

[Wireshark-users] WPA decryption failing

2007-05-21 Thread Bob Carlson
I have version 0.99.5 with AirPcap 2.0. The WPA and WPA2 PSK decryption does not seem to work. I have checked and double checked that the keys are correct. I have tried with and without the SSIDs entered. The passphrases have been entered into the Decryption Keys dialog as WPA-PWD. I have captured

Re: [Wireshark-users] WPA decryption failing

2007-05-21 Thread Soh Kam Yung
On 5/22/07, Bob Carlson [EMAIL PROTECTED] wrote: I have version 0.99.5 with AirPcap 2.0. The WPA and WPA2 PSK decryption does not seem to work. I have checked and double checked that the keys are correct. I have tried with and without the SSIDs entered. The passphrases have been entered into

[Wireshark-users] Stop process in Wireshark 0.99.5

2007-05-21 Thread Horyong Choi
I try to capture the packet by wireshark 0.99.5 with winpcap 4.0 but it is stopping after some seconds. In the task manager of windows xp, it is impossible kill the processor of wireshark.exe. Thus I must reboot for kill the wireshark. Log file is saved in C drive root like ethera02568